Back
CVE-2004-1660
PHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to execute arbitrary PHP code via the cutepath parameter to (1) show_archives.php or (2) show_news.php.
Published: Aug 30, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| cutephp | cutenews | * |
GitHub Security Advisory GHSA-3q3m-3ccv-7882
PHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to...
References (8)
- http://seclists.org/lists/bugtraq/2004/Sep/0014.html Exploit, Vendor Advisory
- http://secunia.com/advisories/12432 Exploit, Vendor Advisory
- http://www.7a69ezine.org/node/view/130 Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17288
- http://seclists.org/lists/bugtraq/2004/Sep/0014.html Exploit, Vendor Advisory
- http://secunia.com/advisories/12432 Exploit, Vendor Advisory
- http://www.7a69ezine.org/node/view/130 Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17288
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.68%
Top 25% most likely to be exploited
Threat Score
30.5 / 100
Data Sources
NVD
EPSS
GitHub