7.5
CVSSv2

CVE-2002-2015

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote malicious users to include arbitrary files and possibly execute code via the caselist parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

postnuke software foundation postnuke 0.703

Exploits

source: wwwsecurityfocuscom/bid/4381/info PostNuke is a content management system originally forked from the PHP-Nuke project It is implemented in PHP, and available for Windows, Linux and other Unix based systems A vulnerability has been reported in some versions of PostNuke Reportedly, it is possible to force the script userphp to ...