5
CVSSv2

CVE-2008-1680

Published: 04/04/2008 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

PHP-Nuke Platinum 7.6.b.5 allows remote malicious users to obtain configuration information via a direct request to maintenance/index.php, which reveals settings such as magic_quotes_gpc.

Vulnerable Product Search on Vulmon Subscribe to Product

future nuke php-nuke platinum 7.6.b.5

Exploits

#!/usr/bin/perl #Inphex use LWP::UserAgent; use LWP::Simple; use IO::Socket; use Switch; #PHP-Nuke Platinum , Forums(Standart) - magic_quotes_gpc = OFF , SQL Injection #nuke_users Structure: #user_id name username user_email femail user_website user_avatar user_regdate user_icq user_occ user_from user_interests user_sig user_viewemail ...