CVE-2008-4557 | Cutephp CuteNews 1.1.1 html.php text code injection (EDB-4851 / XFDB-39450)
A vulnerability, which was classified as very critical, was found in Cutephp CuteNews 1.1.1. Affected is an unknown function of the file plugins/wacko/highlight/html.php. The manipulation of the argument text leads to code injection.
This vulnerability is traded as CVE-2008-4557. It is possible to launch the attack remotely. Furthermore, there is an exploit available.