Vulnerabilities
Vulnerable Software
Cutephp:  >> Cutenews  >> 1.4.0  Security Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) story, or (3) title parameters.
CVSS Score
4.3
EPSS Score
0.099
Published
2006-05-09
CuteNews 1.4.1 and possibly other versions allows remote attackers to obtain the installation path via unspecified vectors involving an invalid file path.
CVSS Score
5.0
EPSS Score
0.005
Published
2006-03-21


Contact Us

Shodan ® - All rights reserved