vendor:
CuteNews
by:
Hamid Ebadi
9,3
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: CuteNews
Affected Version From: 1.4.1
Affected Version To: 1.4.1
Patch Exists: YES
Related CWE: N/A
CPE: a:cutephp:cutenews:1.4.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: All
2008
CuteNews 1.4.1 (CutePHP.com) Hash password Finder
CuteNews 1.4.1 (and Below) is vulnerable to a Remote Code Execution vulnerability. This vulnerability allows an attacker to execute arbitrary code on the vulnerable system. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'command' parameter. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious code to the vulnerable system.
Mitigation:
Upgrade to the latest version of CuteNews 1.4.1 or later.