PT-2003-2413 · Php Nuke · Php-Nuke
Publicado
2003-12-31
·
Atualizado
2017-07-29
·
CVE-2003-1468
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PHP-Nuke versions 6.0 through 6.5 final
Description
The issue allows remote attackers to obtain the full web server path. This is achieved by providing an invalid
cid parameter that is non-numeric or null, resulting in the pathname being leaked in an error message.Recommendations
For PHP-Nuke versions 6.0 through 6.5 final, consider restricting access to the Web Links module until a fix is available, or avoid using non-numeric or null values for the
cid parameter to minimize the risk of path disclosure.Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Php-Nuke