CuteNews1.4.1~ AddCommentForProtectedUserNames~ XSS Attack
Posted by imei on February 20th, 2006——–Summary——–
Software: CuteNews
Sowtware’s Web Site: http://cutephp.com
Versions: 1.4.1
Class: Remote
Status: Unpatched
Exploit: Available
Solution: NotAvailable
Discovered by: imei addmimistrator
Risk Level: Mediume&High
——-Description——-
There is a security bug in CuteNews version 1.4.1 that
allows malicious people to conduct an XSS attack.
This bug is the result of poor checking of user input
(Quotations and
< &>) which are passed to the “show” parameter.
An attacker may use this issue […]