Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-1573
CVE-2004-1573
Description
The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arbitrary PHP code and gain privileges as the administrator.
Affected products
6cpe:2.3:a:cutephp:cutenews:0.88:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:cutephp:cutenews:0.88:*:*:*:*:*:*:*
- cpe:2.3:a:cutephp:cutenews:1.3:*:*:*:*:*:*:*
- cpe:2.3:a:cutephp:cutenews:1.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:cutephp:cutenews:1.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:cutephp:cutenews:1.3.6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- echo.or.id/adv/adv07-y3dips-2004.txtnvdExploitVendor Advisory
- marc.infonvd
- securitytracker.com/idnvd
- www.securityfocus.com/bid/11301nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/17571nvd
News mentions
0No linked articles in our index yet.