CutePHP CuteNews是一套新闻管理系统。该系统具有搜索、文件上传管理、访问控制、备份和恢复等功能。 “废弃”请勿使用此编号。原因:此编号与CNNVD-201110-126编号重复,所有使用CNNVD编号的用户请参考CNNVD-201110-126编号。为防止意外使用,此编号中的所有信息已删除。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Exploits CuteNews 2.1.2 via poor file upload checks used when uploading an avatar image leading to RCE. | https://github.com/mt-code/CVE-2019-11447 | POC Details |
| 2 | CuteNews Avatar 2.1.2 Remote Code Execution Vulnerability | https://github.com/khuntor/CVE-2019-11447-EXP | POC Details |
| 3 | CuteNews 2.1.2 - CVE-2019-11447 Proof-Of-Concept | https://github.com/dinesh876/CVE-2019-11447-POC | POC Details |
| 4 | Exploit Code for CVE-2019-11447 aka CuteNews 2.1.2 Avatar upload RCE (Authenticated) | https://github.com/ColdFusionX/CVE-2019-11447_CuteNews-AvatarUploadRCE | POC Details |
| 5 | CutePHP Cute News 2.1.2 RCE PoC | https://github.com/thewhiteh4t/cve-2019-11447 | POC Details |
| 6 | None | https://github.com/0xConstant/CVE-2019-11447 | POC Details |
| 7 | None | https://github.com/substing/CVE-2019-11447_reverse_shell_upload | POC Details |
| 8 | CuteNews 2.1.2 - CVE-2019-11447 Proof-Of-Concept | https://github.com/CRFSlick/CVE-2019-11447-POC | POC Details |
| 9 | CVE-2019-11447 written in C | https://github.com/ojo5/CVE-2019-11447.c | POC Details |
| 10 | None | https://github.com/banomaly/CVE-2019-11447 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2019-11456 | Gila CMS 跨站请求伪造漏洞 | |
| CVE-2019-11383 | Medha WiFi FTP Server application for Android 信任管理问题漏洞 | |
| CVE-2019-11384 | Zalora application for Android 信任管理问题漏洞 | |
| CVE-2019-5427 | c3p0 资源管理错误漏洞 | |
| CVE-2019-11461 | GNOME Nautilus 安全特征问题漏洞 | |
| CVE-2019-11460 | GNOME gnome-desktop 输入验证错误漏洞 | |
| CVE-2019-11459 | GNOME Evince 缓冲区错误漏洞 | |
| CVE-2019-9955 | 多款ZyXEL产品跨站脚本漏洞 | |
| CVE-2011-3151 | SELinux initscript misuse of touch | |
| CVE-2011-3147 | qcow format could expose host filesystem information | |
| CVE-2011-3145 | mount.ecrpytfs_private sets group owner of /etc/mtab to user's primary group | |
| CVE-2019-11444 | Liferay Portal CE 操作系统命令注入漏洞 | |
| CVE-2019-11455 | Tildeslash Monit 缓冲区错误漏洞 | |
| CVE-2019-11454 | Tildeslash Monit 跨站脚本漏洞 | |
| CVE-2019-11452 | whatsns SQL注入漏洞 | |
| CVE-2019-11451 | whatsns SQL注入漏洞 | |
| CVE-2019-11450 | whatsns SQL注入漏洞 | |
| CVE-2019-11449 | I,Librarian 跨站脚本漏洞 | |
| CVE-2019-11448 | ZOHO ManageEngine Applications Manager SQL注入漏洞 | |
| CVE-2019-11446 | ATutor 代码问题漏洞 |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet