First published: Tue May 09 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) story, or (3) title parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CutePHP CuteNews | =1.4.5 | |
CutePHP CuteNews | =1.3.6 | |
CutePHP CuteNews | =1.3.2 | |
CutePHP CuteNews | =0.88 | |
CutePHP CuteNews | =1.3 | |
CutePHP CuteNews | <=1.4.1 | |
CutePHP CuteNews | =1.4.0 | |
CutePHP CuteNews | =1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.