Remote Code Execution Vulnerability in CuteNews by CuteNews.ru
CVE-2008-4557

Currently unrated

Key Information:

Vendor

CutePHP

Status
Vendor
CVE Published:
14 October 2008

What is CVE-2008-4557?

A security flaw exists in CuteNews version 1.1.1, particularly in the plugins/wacko/highlight/html.php file. This vulnerability allows remote attackers to execute arbitrary PHP code by manipulating the 'text' parameter, which is improperly processed and interpolated into an executable regular expression. Successful exploitation can lead to complete compromise of the affected web application, making it critical for users and administrators to implement necessary security measures.

References

EPSS Score

8% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.