Lucene search

K
cveMitreCVE-2004-2615
HistoryDec 04, 2005 - 11:00 a.m.

CVE-2004-2615

2005-12-0411:00:00
mitre
web.nvd.nist.gov
20
cutenews
security
vulnerability
local user
false news
privileges

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0

Percentile

5.1%

The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions, which allows local users to insert false news, delete news, and possibly gain privileges or have other unknown impact.

Affected configurations

Nvd
Node
cutephpcutenewsMatch1.3.6
VendorProductVersionCPE
cutephpcutenews1.3.6cpe:2.3:a:cutephp:cutenews:1.3.6:*:*:*:*:*:*:*

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0

Percentile

5.1%

Related for CVE-2004-2615