Back
CVE-2005-3010
Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers to execute arbitrary PHP code via the HTTP_CLIENT_IP header (Client-Ip), which is injected into data/flood.db.php.
Published: Sep 21, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| cutephp | cutenews | * |
GitHub Security Advisory GHSA-2j7c-c562-m564
Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php...
References (6)
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
6.34%
Top 7% most likely to be exploited
Threat Score
31.9 / 100
Data Sources
NVD
EPSS
GitHub