CVE-2009-4249
CuteNews 1.4.6 - Cross-Site Scripting via lastusername/mod Parameters and title Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-4249. PoCs published by Andrew Horton.
AI-analyzed exploit summary The provided text describes multiple vulnerabilities in CuteNews and UTF-8 CuteNews, including XSS, HTML injection, and security bypass issues. It includes example URLs demonstrating XSS exploits but does not contain executable exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) lastusername and (2) mod parameters to index.php; and (3) the title parameter to search.php.
Exploits (2)
The provided text describes multiple vulnerabilities in CuteNews and UTF-8 CuteNews, including XSS, HTML injection, and security bypass issues. It includes example URLs demonstrating XSS exploits but does not contain executable exploit code.
This advisory details multiple vulnerabilities in Cute News and UTF-8 Cute News, including XSS, CSRF, LFI, and command injection. It provides technical descriptions and proof-of-concept exploits for each vulnerability, along with affected versions and mitigation steps.