Back

CVE-2003-1240

PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php, (2) search.php, or (3) comments.php.

Published: Dec 31, 2003 Modified: Jun 16, 2026
CWE-94

CVSS Metrics

Affected Products (1)

Vendor Product Version
cutephp cutenews 0.88

GitHub Security Advisory GHSA-xqg7-m89g-c8qg

PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 6.90%

Top 7% most likely to be exploited

Threat Score 32.1 / 100

Data Sources

NVD EPSS GitHub