CutePHP CuteNews Flood Protection Client-IP PHP Code Injection Vulnerability
BID:14869
Info
CutePHP CuteNews Flood Protection Client-IP PHP Code Injection Vulnerability
| Bugtraq ID: | 14869 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 17 2005 12:00AM |
| Updated: | Sep 17 2005 12:00AM |
| Credit: | Discovery is credited to retrogod. |
| Vulnerable: |
CutePHP CuteNews 1.4 .0 |
| Not Vulnerable: | |
Discussion
CutePHP CuteNews Flood Protection Client-IP PHP Code Injection Vulnerability
CutePHP CuteNews is prone to a vulnerability that may let remote attackers inject PHP and execute PHP code. This is due to an input validation error that lets remote users inject PHP code into a temporary file used by the flood protection feature of the application.
Exploitation could allow for remote execution of PHP code in the context of the server hosting the application.
This issue is reported to affected CuteNews 1.4.0. Other versions may also be affected.
CutePHP CuteNews is prone to a vulnerability that may let remote attackers inject PHP and execute PHP code. This is due to an input validation error that lets remote users inject PHP code into a temporary file used by the flood protection feature of the application.
Exploitation could allow for remote execution of PHP code in the context of the server hosting the application.
This issue is reported to affected CuteNews 1.4.0. Other versions may also be affected.
Exploit / POC
CutePHP CuteNews Flood Protection Client-IP PHP Code Injection Vulnerability
There is no exploit required. However, the following exploit code was provided:
There is no exploit required. However, the following exploit code was provided:
Solution / Fix
CutePHP CuteNews Flood Protection Client-IP PHP Code Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
CutePHP CuteNews Flood Protection Client-IP PHP Code Injection Vulnerability
References:
References: