Vulnerabilities > CVE-2004-1659 - Cross-Site Scripting vulnerability in CuteNews 'index.php'

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
cutephp
nessus
exploit available

Summary

Cross-site scripting (XSS) vulnerability in index.php in CuteNews 1.3.6 and earlier allows remote attackers with Administrator, Editor, Journalist or Commenter privileges to inject arbitrary web script or HTML via the mod parameter.

Exploit-Db

descriptionCuteNews 0.88/1.3.x 'index.php' Cross-Site Scripting Vulnerability. CVE-2004-1659. Webapps exploit for php platform
idEDB-ID:24566
last seen2016-02-02
modified2004-09-02
published2004-09-02
reporterExoduks
sourcehttps://www.exploit-db.com/download/24566/
titleCuteNews 0.88/1.3.x - 'index.php' Cross-Site Scripting Vulnerability

Nessus

NASL familyCGI abuses : XSS
NASL idCUTENEWS_INDEXPHP_XSS.NASL
descriptionThe version of CuteNews installed on the remote host is vulnerable to a cross-site scripting (XSS) attack. An attacker, exploiting this flaw, would need to be able to coerce a user to browse to a purposefully malicious URI. Upon successful exploitation, the attacker would be able to run code within the web-browser in the security context of the CuteNews server.
last seen2020-06-01
modified2020-06-02
plugin id14665
published2004-09-06
reporterThis script is Copyright (C) 2004-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/14665
titleCuteNews index.php mod Parameter XSS