PT-2004-2720 · Php Nuke · 4Nalbum

Janek Vind

+1

·

Published

2004-03-15

·

Updated

2017-07-11

·

CVE-2004-1821

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions 4nalbum versions 0.92 for PHP-Nuke 6.5 through 7.0
Description The issue allows remote attackers to gain privileges or perform unauthorized database operations. This is achieved via the gid parameter.
Recommendations For 4nalbum version 0.92, avoid using the gid parameter in affected API endpoints until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1821

Affected Products

4Nalbum