Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Static code injection vulnerability in the Categories module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote authenticated users with application administrative privileges to inject arbitrary PHP code into data/category.db.php via the Category Access field.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CutePHP CuteNews Categories模块代码注入漏洞
Vulnerability Description
CutePHP CuteNews 1.4.6版本和UTF-8 CuteNews 8b版本之前的版本的Categories模块中存在静态代码注入漏洞。具有申请管理特权的远程验证用户可以借助Category访问字段,向data/category.db.php注入任意PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A