Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CutePHP CuteNews目录遍历漏洞
Vulnerability Description
Cutenews是一款功能强大的新闻管理系统,使用二维表格式文本文件存储数据。 CuteNews 1.4.1中的目录遍历漏洞可让远程攻击者通过(1) show_archives.php和(2) show_news.php的模板参数中的"../"序列来包含任意文件、执行代码以及取得特权。
CVSS Information
N/A
Vulnerability Type
N/A