PT-2001-2179 · Php · Php-Nuke

Published

2001-09-24

·

Updated

2017-10-10

·

CVE-2001-1032

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP-Nuke versions 5.2 and earlier, except 5.0RC1
Description The issue allows remote attackers to copy and upload arbitrary files and read the PHP-Nuke configuration file by directly calling the "admin.php" endpoint with an upload parameter and specifying the file to copy. This is due to the lack of login credential checks for upload operations in the affected versions.
Recommendations For PHP-Nuke versions 5.2 and earlier, except 5.0RC1, consider restricting access to the "admin.php" endpoint to prevent unauthorized file uploads until a fix is available. As a temporary workaround, disable the upload functionality in "admin.php" to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1032

Affected Products

Php-Nuke