Total vulnerabilities in the database
Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.
Software | From | Fixed in |
---|---|---|
cutephp / cutenews | - | 1.3.6.x |