HTTP: CuteNews Debug Information Disclosure

This signature detects attempts to exploit a known vulnerability in CuteNews 1.3, a news management system. Attackers can send a debug query to obtain information that was returned from a call to the phpinfo() function.

Extended Description

An information disclosure weakness has been reported in CuteNews 1.3, that may expose sensitive server configuration data. The problem occurs due to CuteNews accepting a debug query that will result in the exposure of information returned from a call to the phpinfo() function. A malicious person could potentially use information harvested through the exploitation this type of issue to launch future attacks against a target system.

Affected Products

Cutephp cutenews

Short Name
HTTP:INFO-LEAK:CUTENEWS
Severity
Warning
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CuteNews Debug Disclosure Information bid:9130
Release Date
01/08/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Cutephp

Found a potential security threat?