4.3
CVSSv2

CVE-2003-1371

Published: 31/12/2003 Updated: 29/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Nuked-Klan 1.3b, and possibly earlier versions, allows remote malicious users to obtain sensitive server information via an op parameter set to phpinfo for the (1) Team, (2) News, or (3) Liens modules.

Vulnerable Product Search on Vulmon Subscribe to Product

nuked-klan nuked-klan 1.3_beta

Exploits

source: wwwsecurityfocuscom/bid/6917/info A vulnerability has been discovered in Nuked-Klan which may be exploited to execute certain PHP functions on a target server This issue occurs in the 'Team', 'News', and 'Lien' modules and is due to insufficient sanitization of user-supplied URI parameters This issue may be exploited by a remot ...