Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php.
Link | Tags |
---|---|
http://www.osvdb.org/20474 | vdb entry |
http://www.osvdb.org/20473 | vdb entry |
http://secunia.com/advisories/17435 | third party advisory vendor advisory |
http://www.osvdb.org/20472 | vdb entry |
http://rgod.altervista.org/cute141.html | exploit vendor advisory |
http://www.vupen.com/english/advisories/2005/2296 | vdb entry |
http://www.securityfocus.com/bid/15295 | vdb entry |