PT-2005-1495 · Php · Php-Nuke
Janek Vind
+1
·
Published
2005-02-15
·
Updated
2017-07-11
·
CVE-2005-0433
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Php-Nuke version 7.5
Description
The issue allows remote attackers to determine the full path of the web server via invalid or missing arguments to certain PHP files, including "db.php", "mainfile.php", "Downloads/index.php", or "Web Links/index.php". This is possible because the PHP error message lists the path when such invalid or missing arguments are provided.
Recommendations
For Php-Nuke version 7.5, consider restricting access to the affected PHP files, such as "db.php", "mainfile.php", "Downloads/index.php", and "Web Links/index.php", to prevent remote attackers from determining the full path of the web server. Additionally, as a temporary workaround, consider disabling the display of PHP error messages to minimize the risk of path disclosure.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Php-Nuke