| VID |
21191 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The opendir.php script in the PHP-Nuke allows remote attackers to read arbitrary files by specifying the filename as an argument to the requesturl parameter. PHP-Nuke is an open-source program for creating and managing news-based Web sites created by Francisco Burzi. Successfully exploiting this vulnerability, a remote attacker could read arbitrary files on the affected Web server with the privileges of the HTTP daemon.
* References: http://archives.neohapsis.com/archives/bugtraq/2001-02/0214.html http://archives.neohapsis.com/archives/bugtraq/2001-02/0225.html
* Platforms Affected: UNIX/Linux Any version Windows Any version |
| Recommendation |
Upgrade to the latest version of PHP-Nuke (6.5 or later), available from the PHP-Nuke Developer's Official Web site, http://www.phpnuke.org .
-- OR --
De-install this package and use something else. |
| Related URL |
CVE-2001-0321 (CVE) |
| Related URL |
(SecurityFocus) |
| Related URL |
6512 (ISS) |
|