vendor:
CuteNews and UTF-8 CuteNews
by:
Unknown
7.5
CVSS
HIGH
Cross-site scripting, HTML-injection, information-disclosure, arbitrary-script-injection, and security-bypass issues
Unknown
CWE
Product Name: CuteNews and UTF-8 CuteNews
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested:
Unknown
Multiple vulnerabilities in CuteNews and UTF-8 CuteNews
The vulnerabilities in CuteNews and UTF-8 CuteNews allow attackers to obtain sensitive information, gain unauthorized access, run arbitrary script code in the browser, hijack user sessions, and execute arbitrary commands in the context of the webserver process. Exploits for some of the issues may require administrator privilege.
Mitigation:
Unknown