First published: Wed Dec 02 2009(Updated: )
CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to obtain sensitive information via an invalid date value in the from_date_day parameter to search.php, which reveals the installation path in an error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CutePHP CuteNews | =1.4.6 | |
Korn19 Utf-8 Cutenews | =8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4175 has been classified as a moderate severity vulnerability due to its potential for information disclosure.
To fix CVE-2009-4175, upgrade to the latest version of CuteNews or ensure proper input validation for the from_date_day parameter.
Exploiting CVE-2009-4175 can allow attackers to reveal sensitive information such as the installation path of the CuteNews application.
CVE-2009-4175 affects CuteNews 1.4.6 and earlier versions, as well as UTF-8 CuteNews version 8.
Yes, CVE-2009-4175 can be exploited remotely by sending an invalid date value through the from_date_day parameter.