Korean
<< Back
VID 21409
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The CuteNews has a 'mod' variable Cross-Site Scripting Vulnerability.
CuteNews is a freely available PHP based news management program that uses flat files to store the database. CuteNews 1.3.6 and earlier are vulnerable to a Cross-Site Scripting vulnerability, caused by a failure of the application to properly sanitize user-supplied input. A remote attacker could create a specially crafted URL link to 'index.php' script containing malicious scripts in the 'mod' variable, and then could persuade a target user to click it. Once the URL is clicked, the embedded codes would be executed in the victim's Web browser. A remote attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

* References:
http://www.osvdb.org/displayvuln.php?osvdb_id=9558

* Platforms Affected:
CuteNews 1.3.6 and earlier
Linux Any version
Unix Any version
Microsoft Windows Any version
Recommendation No upgrade or patch available as of December 2004.

Upgrade to the new version of CuteNews, when new version fixed this problem becomes available from the CutePHP Web site at http://cutephp.com/
Related URL CVE-2004-1659 (CVE)
Related URL 11097 (SecurityFocus)
Related URL 17214 (ISS)