5
CVSSv2

CVE-2001-0383

Published: 18/06/2001 Updated: 10/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

banners.php in PHP-Nuke 4.4 and previous versions allows remote malicious users to modify banner ad URLs by directly calling the Change operation, which does not require authentication.

Vulnerable Product Search on Vulmon Subscribe to Product

francisco burzi php-nuke

Exploits

source: wwwsecurityfocuscom/bid/2544/info PHP-Nuke is a website creation/maintainence tool written in PHP3 A PHP-Nuke feature supporting cycling ad banners is subject to interference from a remote user A querystring can be submitted to an unpatched server which allows the remote user to specify a new destination URL to be opened in a ...