Back

CVE-2005-3507

Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php.

Published: Nov 6, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
cutephp cutenews *

GitHub Security Advisory GHSA-w678-q7pr-w52j

Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 12.45%

Top 4% most likely to be exploited

Threat Score 23.7 / 100

Data Sources

NVD EPSS GitHub