5
CVSSv2

CVE-2004-1937

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in Nuked-KlaN 1.4b and 1.5b allow remote malicious users to read or include arbitrary files via .. sequences in (1) the user_langue parameter to index.php or (2) the langue parameter to update.php, or modify arbitrary GLOBAL variables by causing globals.php to be loaded before conf.inc.php via (3) .. sequences in the file parameter with the page parameter set to globals, or (4) ../globals.php in the user_langue parameter, as demonstrated by modifying $nuked[prefix] in the Suggest module.

Vulnerable Product Search on Vulmon Subscribe to Product

nuked-klan nuked-klan 1.3

nuked-klan nuked-klan 1.3_beta

nuked-klan nuked-klan 1.4

nuked-klan nuked-klan 1.5

nuked-klan nuked-klan 1.5_sp2

nuked-klan nuked-klan 1.2

nuked-klan nuked-klan 1.2_beta

Exploits

source: wwwsecurityfocuscom/bid/10104/info Nuked-Klan is prone to multiple vulnerabilities These issues include information disclosure via inclusion of local files, an issue that may permit remote attackers to corrupt configuration files and an SQL injection vulnerability - To include a local file: wwwexamplecom/indexphp?use ...