PT-2002-2736 · Postnuke · Postnuke

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-2015

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PostNuke version 0.703
Description The issue allows remote attackers to include arbitrary files and possibly execute code. This is achieved via the caselist parameter in the user.php file.
Recommendations For PostNuke version 0.703, consider restricting access to the user.php file or the caselist parameter to minimize the risk of exploitation. Avoid using the caselist parameter in the affected file until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-2015

Affected Products

Postnuke