PT-2002-1574 · Asp Nuke · Asp-Nuke

Published

2002-06-11

·

Updated

2008-09-05

·

CVE-2002-0524

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ASP-Nuke versions RC2 and earlier
Description The issue allows remote attackers to determine the absolute path of the server. This can be achieved by either calling the "database-inc.asp" endpoint with incorrect cookies or by calling the "Post.asp" endpoint with certain arguments, which results in the pathname being leaked in an error message.
Recommendations For ASP-Nuke versions RC2 and earlier, consider restricting access to the "database-inc.asp" and "Post.asp" endpoints until a fix is available. As a temporary workaround, modify the error handling mechanism to prevent the disclosure of sensitive path information.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0524

Affected Products

Asp-Nuke