Unrated severityNVD Advisory· Published Dec 10, 2009· Updated Apr 23, 2026
CVE-2009-4249
CVE-2009-4249
Description
Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) lastusername and (2) mod parameters to index.php; and (3) the title parameter to search.php.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.morningstarsecurity.com/advisories/MORNINGSTAR-2009-02-CuteNews.txtnvdExploit
- www.securityfocus.com/bid/36971nvdExploit
- www.securityfocus.com/archive/1/507782/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/54219nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/54220nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/54222nvd
News mentions
0No linked articles in our index yet.