Korean
<< Back
VID 21191
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The opendir.php script in the PHP-Nuke allows remote attackers to read arbitrary files by specifying the filename as an argument to the requesturl parameter.
PHP-Nuke is an open-source program for creating and managing news-based Web sites created by Francisco Burzi. Successfully exploiting this vulnerability, a remote attacker could read arbitrary files on the affected Web server with the privileges of the HTTP daemon.

* References:
http://archives.neohapsis.com/archives/bugtraq/2001-02/0214.html
http://archives.neohapsis.com/archives/bugtraq/2001-02/0225.html

* Platforms Affected:
UNIX/Linux Any version
Windows Any version
Recommendation Upgrade to the latest version of PHP-Nuke (6.5 or later), available from the PHP-Nuke Developer's Official Web site, http://www.phpnuke.org .

-- OR --

De-install this package and use something else.
Related URL CVE-2001-0321 (CVE)
Related URL (SecurityFocus)
Related URL 6512 (ISS)