peter bassill · operator
$ cve CVE-2008-4557 JSON

CVE-2008-4557 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 45.3% (pctl 99)

Patch early

A public exploit exists.

Description

plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbitrary PHP code via the text parameter, which is inserted into an executable regular expression.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS45.34% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2008-10-14
Last modified2026-06-16

Affected (1)

VendorProduct
cutephpcutenews

Public exploits

SourceTitleDate
exploit-dbCuteNews 1.1.1 - 'html.php' Remote Code Execution2008-01-06

References

→ the Explorer  ·  watch your stack  ·  NVD