PT-2001-2054 · Php Nuke · Network Tools

Published

2001-11-16

·

Updated

2019-07-01

·

CVE-2001-0899

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Network Tools version 0.2 for PHP-Nuke
Description The issue allows remote attackers to execute commands on the server. This is achieved by injecting shell metacharacters in the hostinput variable.
Recommendations For Network Tools version 0.2, consider restricting or sanitizing input to the hostinput variable to prevent command execution until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0899

Affected Products

Network Tools