PT-2003-1487 · Php Nuke · Php-Nuke
Albert Puigsech Galicia
·
Publicado
2003-05-14
·
Atualizado
2017-07-11
·
CVE-2003-0279
CVSS v2.0
2.6
Baixa
| Vetor | AV:N/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
PHP-Nuke versions 5.x through 6.5
Description:
The issue allows remote attackers to steal sensitive information via numeric fields. This can be demonstrated using the
viewlink function and cid parameter, or through index.php.Recommendations:
For PHP-Nuke versions 5.x through 6.5, consider restricting access to the Web Links module until a patch is available. As a temporary workaround, avoid using numeric fields in the Web Links module to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Php-Nuke