Skip to main content

Vendor/product archive

korn19 / utf-8_cutenews CVEs

Beta · best-effort

6 CVEs tagged to korn19 / utf-8_cutenews0 Critical, 0 High, 5 Medium, 1 Low, 0 Unrated.

CVE-2009-4250

Published Dec 10, 2009

Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allow remote attackers to inject arbitrary web script or HTML via (1) th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4175

Published Dec 2, 2009

CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to obtain sensitive information via an invalid date value in the from_date_day parameter to search.php,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4174

Published Dec 2, 2009

The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with Journalist or Editor access t…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4173

Published Dec 2, 2009

Cross-site request forgery (CSRF) vulnerability in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to hijack the authentication of administrators for r…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4172

Published Dec 2, 2009

Cross-site scripting (XSS) vulnerability in index.php in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews 8 and 8b, when magic_quotes_gpc is disabled, allows remote attackers to inject a…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4113

Published Nov 30, 2009

Static code injection vulnerability in the Categories module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote authenticated users with application administrati…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1