PT-2002-1571 · Asp Nuke · Asp-Nuke

Published

2002-06-11

·

Updated

2008-09-05

·

CVE-2002-0521

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ASP-Nuke versions prior to RC2
Description The issue allows remote attackers to execute script or gain privileges as other ASP-Nuke users. This can be achieved via script in the name parameter in "downloads.asp", the message parameter in "Post.asp", or a web site URL in "profile.asp".
Recommendations For ASP-Nuke versions prior to RC2, consider disabling the affected parameters, such as name in "downloads.asp", message in "Post.asp", to minimize the risk of exploitation until a fix is available. Restrict access to "profile.asp" to prevent attackers from using a malicious web site URL.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0521

Affected Products

Asp-Nuke