Vulnerabilities > CVE-2006-1925 - Cross-Site Scripting vulnerability in Cutephp Cutenews 1.4.1

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
cutephp
exploit available

Summary

Directory traversal vulnerability in the editnews module (inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote attackers to read or modify files via the source parameter in the (1) editnews or (2) doeditnews action. NOTE: this can also produce resultant XSS when the target file does not exist.

Vulnerable Configurations

Part Description Count
Application
Cutephp
1

Exploit-Db

descriptionCutePHP CuteNews 1.4.1 Editnews Module Cross-Site Scripting Vulnerability. CVE-2006-1925. Webapps exploit for php platform
idEDB-ID:27676
last seen2016-02-03
modified2006-04-19
published2006-04-19
reporterLoK-Crew
sourcehttps://www.exploit-db.com/download/27676/
titleCutePHP CuteNews 1.4.1 Editnews Module Cross-Site Scripting Vulnerability