First published: Tue May 09 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) story, or (3) title parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CutePHP CuteNews | =1.4.5 | |
CutePHP CuteNews | =1.3.6 | |
CutePHP CuteNews | =1.3.2 | |
CutePHP CuteNews | =0.88 | |
CutePHP CuteNews | =1.3 | |
CutePHP CuteNews | <=1.4.1 | |
CutePHP CuteNews | =1.4.0 | |
CutePHP CuteNews | =1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2249 has been assessed as a medium-level severity vulnerability due to its potential for exploitation via cross-site scripting.
To fix CVE-2006-2249, upgrade to at least CuteNews version 1.4.6 or later, which addresses the XSS vulnerabilities.
CVE-2006-2249 affects multiple versions of CuteNews, particularly versions 1.4.1 and earlier, and possibly 1.4.5.
CVE-2006-2249 involves multiple cross-site scripting (XSS) vulnerabilities in the search.php file that allow attackers to inject arbitrary web scripts or HTML.
Web administrators and users of affected versions of CuteNews are at risk from CVE-2006-2249’s vulnerabilities.