CVE-2009-4174
CuteNews 1.4.6 and UTF-8 CuteNews < 8b - Authenticated Article Modification via ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4174. PoCs published by Andrew Horton.
AI-analyzed exploit summary The provided text describes multiple vulnerabilities in CuteNews and UTF-8 CuteNews, including information disclosure via path traversal in the 'source' parameter. No executable exploit code is present, only URLs demonstrating the vulnerability.
Description
The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with Journalist or Editor access to bypass administrative moderation and edit previously submitted articles via a modified id parameter in a doeditnews action.
Exploits (1)
The provided text describes multiple vulnerabilities in CuteNews and UTF-8 CuteNews, including information disclosure via path traversal in the 'source' parameter. No executable exploit code is present, only URLs demonstrating the vulnerability.