CVE-2008-4557
high · 10plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbitrary PHP code via the text parameter, which is inserted into an executable regular expression.
10
CVSS
45.3%
EPSS (exploit prob.)
99th
EPSS percentile
2008-10-14
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| cutephp | cutenews | 1.1.1 |
Check a specific version with /api/v1/cve/match.
References
- http://secunia.com/advisories/28330
- http://securityreason.com/securityalert/4403
- http://www.osvdb.org/40236
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39450
- https://www.exploit-db.com/exploits/4851
- http://secunia.com/advisories/28330
- http://securityreason.com/securityalert/4403
- http://www.osvdb.org/40236
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39450
- https://www.exploit-db.com/exploits/4851
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2008-4557