First published: Mon Nov 30 2009(Updated: )
Static code injection vulnerability in the Categories module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote authenticated users with application administrative privileges to inject arbitrary PHP code into data/category.db.php via the Category Access field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CutePHP CuteNews | =1.4.6 | |
Korn19 Utf-8 Cutenews | =8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4113 is classified as a high-severity vulnerability due to its ability to allow remote authenticated users to execute arbitrary PHP code.
To fix CVE-2009-4113, you should upgrade to the latest version of CuteNews or apply security patches that address this vulnerability.
CVE-2009-4113 affects remote authenticated users with administrative privileges on CuteNews version 1.4.6 and UTF-8 CuteNews versions prior to 8b.
An attacker can execute remote code injection attacks by exploiting the static code injection vulnerability in the Categories module.
Yes, there are known exploits for CVE-2009-4113 that demonstrate how the vulnerability can be leveraged to inject arbitrary PHP code.