PT-2004-2905 · Nukejokes · Nukejokes

Published

2004-05-08

·

Updated

2017-07-11

·

CVE-2004-2009

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions NukeJokes versions 1.7 through 2 Beta
Description The issue allows remote attackers to obtain the full path of the server. This can be achieved through a direct call to "mainfunctions.php", an invalid jokeid parameter in the JokeView function, or an invalid cat parameter in the CatView function. In each case, the path is revealed in a PHP error message.
Recommendations For NukeJokes versions 1.7 through 2 Beta, consider restricting access to "mainfunctions.php" and validating the jokeid and cat parameters in the JokeView and CatView functions, respectively, to prevent the disclosure of the server path.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2009

Affected Products

Nukejokes