PT-2005-1495 · Php · Php-Nuke

Janek Vind

+1

·

Published

2005-02-15

·

Updated

2017-07-11

·

CVE-2005-0433

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Php-Nuke version 7.5
Description The issue allows remote attackers to determine the full path of the web server via invalid or missing arguments to certain PHP files, including "db.php", "mainfile.php", "Downloads/index.php", or "Web Links/index.php". This is possible because the PHP error message lists the path when such invalid or missing arguments are provided.
Recommendations For Php-Nuke version 7.5, consider restricting access to the affected PHP files, such as "db.php", "mainfile.php", "Downloads/index.php", and "Web Links/index.php", to prevent remote attackers from determining the full path of the web server. Additionally, as a temporary workaround, consider disabling the display of PHP error messages to minimize the risk of path disclosure.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0433

Affected Products

Php-Nuke