PT-2001-1239 · Php · Php-Nuke
Publicado
2001-06-02
·
Atualizado
2017-10-10
·
CVE-2001-0001
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
PHP-Nuke version 4.4
Description:
The issue allows users to bypass authentication and gain access to other user accounts by extracting authentication information from a cookie, specifically through the cookiedecode function in PHP-Nuke.
Recommendations:
For PHP-Nuke version 4.4, consider disabling the cookiedecode function as a temporary workaround until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation. Avoid using the cookiedecode function for authentication purposes until the issue is resolved.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Php-Nuke