7.5
CVSSv2

CVE-2004-2044

Published: 01/06/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER['PHP_SELF'] to identify the calling script, which allows remote malicious users to directly access scripts, obtain path information via a PHP error message, and possibly gain access, as demonstrated using an HTTP request that contains the "admin.php" string.

Vulnerable Product Search on Vulmon Subscribe to Product

francisco burzi php-nuke 5.3.1

francisco burzi php-nuke 5.4

francisco burzi php-nuke 6.5_rc2

francisco burzi php-nuke 6.5_rc3

francisco burzi php-nuke 7.2

francisco burzi php-nuke 7.3

francisco burzi php-nuke 5.0

francisco burzi php-nuke 5.5

francisco burzi php-nuke 5.6

francisco burzi php-nuke 6.6

francisco burzi php-nuke 6.7

oscommerce osc2nuke 7x_1.0

paul laudanski betanc php-nuke bundle

francisco burzi php-nuke 5.0.1

francisco burzi php-nuke 5.1

francisco burzi php-nuke 6.0

francisco burzi php-nuke 6.5

francisco burzi php-nuke 6.9

francisco burzi php-nuke 7.0

francisco burzi php-nuke 5.2

francisco burzi php-nuke 5.2a

francisco burzi php-nuke 6.5_beta1

francisco burzi php-nuke 6.5_final

francisco burzi php-nuke 6.5_rc1

francisco burzi php-nuke 7.0_final

francisco burzi php-nuke 7.1

trustix secure linux 2.0

trustix secure linux 2.1

Exploits

source: wwwsecurityfocuscom/bid/10447/info PHP-Nuke is affected by a direct script access security vulnerability This issue is due to a failure to properly validate the location and name of the file being accessed This issue will allow an attacker to gain access to sensitive scripts such as the 'adminphp' script The attacker may be a ...