PT-2004-2914 · Php Nuke · Php-Nuke
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-2018
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Php-Nuke versions 6.x through 7.3
Description
The issue allows remote attackers to execute arbitrary PHP code by modifying the
modpath parameter to reference a URL on a remote web server that contains the code. This can be done through the index.php file.Recommendations
For Php-Nuke versions 6.x through 7.3, consider restricting access to the
modpath parameter to prevent remote attackers from executing arbitrary PHP code until a patch is available. Avoid using the modpath parameter to reference URLs on remote web servers.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Php-Nuke