Sploitus

CVE-2004-0660

5 known exploits for CVE-2004-0660

Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in CuteNews 1.3.1 allows remote attackers to inject arbitrary script or HTML via the id parameter.

Affected products
Cutenews
Cutephp Cutenews
= 0.88, 1.3, 1.3.1
Fix
Available
CVSS 2.0
6.8 MEDIUM
EPSS
3.9% (90th percentile)
NVD status
Modified
Published
2004-07-13
CVE-2004-0660 at NVD
Authoritative description, scoring and affected products

5 known exploits for CVE-2004-0660

Proof-of-concept code and exploit modules indexed by Sploitus