PT-2001-1239 · Php · Php-Nuke

Published

2001-06-02

·

Updated

2017-10-10

·

CVE-2001-0001

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: PHP-Nuke version 4.4
Description: The issue allows users to bypass authentication and gain access to other user accounts by extracting authentication information from a cookie, specifically through the cookiedecode function in PHP-Nuke.
Recommendations: For PHP-Nuke version 4.4, consider disabling the cookiedecode function as a temporary workaround until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation. Avoid using the cookiedecode function for authentication purposes until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0001

Affected Products

Php-Nuke