7.5
CVSSv2

CVE-2002-0206

Published: 16/05/2002 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

index.php in Francisco Burzi PHP-Nuke 5.3.1 and previous versions, and possibly other versions prior to 5.5, allows remote malicious users to execute arbitrary PHP code by specifying a URL to the malicious code in the file parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

francisco burzi php-nuke 1.0

francisco burzi php-nuke 5.0.1

francisco burzi php-nuke 5.1

francisco burzi php-nuke 4.3

francisco burzi php-nuke 4.4

francisco burzi php-nuke 5.3.1

francisco burzi php-nuke 4.4.1a

francisco burzi php-nuke 5.0

francisco burzi php-nuke 2.5

francisco burzi php-nuke 3.0

francisco burzi php-nuke 4.0

francisco burzi php-nuke 5.2

francisco burzi php-nuke 5.2a

Exploits

source: wwwsecurityfocuscom/bid/3889/info PHPNuke is a website creation/maintenance tool The 'indexphp' script has a feature which allows users to include files Due to insufficent input validation, it is possible to include files located on a remote server Arbitrary code in the attacker's included file may be executed As one conseq ...