Static Code Injection Vulnerability in CuteNews by CuteNews
CVE-2005-3010

Currently unrated

Key Information:

Vendor

CutePHP

Status
Vendor
CVE Published:
21 September 2005

What is CVE-2005-3010?

A static code injection vulnerability exists within the flood protection feature of CuteNews 1.4.0 and earlier. This security flaw allows remote attackers to inject arbitrary PHP code via the HTTP_CLIENT_IP header, which interacts with the flood database, creating potential for unauthorized script execution. Proper validation and sanitization of incoming data are crucial to mitigate this risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.