6.8
CVSSv2

CVE-2003-1436

Published: 31/12/2003 Updated: 29/07/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote malicious users to execute arbitrary PHP code via the filhead parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

crossnuke nukebrowser 2.41

crossnuke nukebrowser 2.5

crossnuke nukebrowser 2.1

crossnuke nukebrowser 2.11

crossnuke nukebrowser 2.20

crossnuke nukebrowser 2.3

Exploits

source: wwwsecurityfocuscom/bid/6731/info Nukebrowser is prone to an issue which may allow remote attackers to include files located on remote servers This issue is present in the nukebrowserphp script file Under some circumstances, it is possible for remote attackers to influence the include path for 'cmdtxt' to point to an external ...