Vulnerability CVE-2008-4557


Published: 2008-10-14   Modified: 2012-02-12

Description:
plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbitrary PHP code via the text parameter, which is inserted into an executable regular expression.

See advisories in our WLB2 database:
Topic
Author
Date
High
CuteNews 1.1.1 (html.php) Remote Code Execution Vulnerability
ITDEFENCE
16.10.2008

Type:

CWE-94

(Improper Control of Generation of Code ('Code Injection'))

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Cutephp -> Cutenews 

 References:
http://xforce.iss.net/xforce/xfdb/39450
http://www.osvdb.org/40236
http://www.milw0rm.com/exploits/4851
http://securityreason.com/securityalert/4403
http://secunia.com/advisories/28330

Copyright 2024, cxsecurity.com

 

Back to Top