neosecurityteam.net
http://neosecurityteam.net/index.php?action=advisories&id=21 CVE-2006-2249
CuteNews 1.4.1 - 'search.php' Multiple Cross-Site Scripting Vulnerabilities
Record summary
CVE-2006-2249 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) story, or (3) title parameters.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCuteNews 1.4.1 - 'search.php' Multiple Cross-Site Scripting VulnerabilitiesExploitDB exploitby NSTNot analyzed1 file
References
920026Third-party advisory
http://secunia.com/advisories/20026 860Third-party advisory
http://securityreason.com/securityalert/860 25304vdb entry
http://www.osvdb.org/25304 20060505 CuteNews 1.4.1 Multiple vulnerabilitiesmailing list
http://www.securityfocus.com/archive/1/433058/100/0/threaded 17850vdb entry
http://www.securityfocus.com/bid/17850 ADV-2006-1683vdb entry
http://www.vupen.com/english/advisories/2006/1683 cutenews-search-parameters-xss(26270)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/26270 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-2249