PT-2002-1571 · Asp Nuke · Asp-Nuke
Published
2002-06-11
·
Updated
2008-09-05
·
CVE-2002-0521
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ASP-Nuke versions prior to RC2
Description
The issue allows remote attackers to execute script or gain privileges as other ASP-Nuke users. This can be achieved via script in the
name parameter in "downloads.asp", the message parameter in "Post.asp", or a web site URL in "profile.asp".Recommendations
For ASP-Nuke versions prior to RC2, consider disabling the affected parameters, such as
name in "downloads.asp", message in "Post.asp", to minimize the risk of exploitation until a fix is available. Restrict access to "profile.asp" to prevent attackers from using a malicious web site URL.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Asp-Nuke