Vulnerabilities
Vulnerable Software
Cutephp:  >> Cutenews  >> 1.4.0  Security Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) story, or (3) title parameters.
CVSS Score
4.3
EPSS Score
0.021
Published
2006-05-09
CuteNews 1.4.1 and possibly other versions allows remote attackers to obtain the installation path via unspecified vectors involving an invalid file path.
CVSS Score
5.0
EPSS Score
0.015
Published
2006-03-21


Contact Us

Shodan ® - All rights reserved