CVE-2009-4249
CutePHP CuteNews 1.4.6 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) lastusername and (2) mod parameters to index.php; and (3) the title parameter to search.php.
Exploits (2)
exploitdb
WRITEUP
VERIFIED
by Andrew Horton · textwebappsphp
https://www.exploit-db.com/exploits/33342
References (6)
Scores
EPSS
0.0342
EPSS Percentile
87.3%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
cutephp/cutenews
n/a/n/a
Timeline
Published
Dec 10, 2009
Tracked Since
Feb 18, 2026