PT-2001-1239 · Php · Php-Nuke
Published
2001-06-02
·
Updated
2017-10-10
·
CVE-2001-0001
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
PHP-Nuke version 4.4
Description:
The issue allows users to bypass authentication and gain access to other user accounts by extracting authentication information from a cookie, specifically through the cookiedecode function in PHP-Nuke.
Recommendations:
For PHP-Nuke version 4.4, consider disabling the cookiedecode function as a temporary workaround until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation. Avoid using the cookiedecode function for authentication purposes until the issue is resolved.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Php-Nuke