Sploitus

CVE-2009-4249

2 known exploits for CVE-2009-4249

Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) lastusername and (2) mod parameters to index.php; and (3) the title parameter to search.php.

Affected products
Cutenews
Cutephp Cutenews
= 1.4.6
Fix
Available
CVSS 2.0
2.6 LOW
EPSS
1.9% (78th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2009-12-10
CVE-2009-4249 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2009-4249

Proof-of-concept code and exploit modules indexed by Sploitus