PT-2005-2021 · Php · Php-Nuke
Cxib8O3
+1
·
Published
2005-04-07
·
Updated
2016-10-18
·
CVE-2005-0998
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PHP-Nuke version 7.6
Description
The issue allows remote attackers to obtain sensitive information via an invalid
show parameter. This triggers a division by zero PHP error, which leaks the full pathname of the server.Recommendations
For PHP-Nuke version 7.6, consider restricting access to the Web Links module until a patch is available. As a temporary workaround, avoid using the
show parameter in the affected module to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Php-Nuke