| VID |
21293 |
| Severity |
20 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The PostNuke, installed on the Web server, is vulnerable to multiple Path Disclosure Vulnerabilities. PostNuke, developed by Francisco Burzi, is a PHP content management system with a MySQL database. The version 0.7.2.6 of PostNuke allows a remote attacker to obtain the installation path of PostNuke by sending a HTTP request directly to many scripts in the "includes/blocks/" or "pnadodb" directory or the "NS-NewUser", "NS-Your_Account", "NS-LostPassword", "NS-Multisites" or "NS-User" module. A remote attacker could send a specially-crafted HTTP request to these vulnerable scripts, which would cause an error message to be returned that contains the installation path of PostNuke.
* References: http://archives.neohapsis.com/archives/fulldisclosure/2004-03/2336.html
* Platforms Affected: PostNuke Phoenix 0.7.2.6 UNIX/Linux Any version Windows Any version |
| Recommendation |
No patch or upgrade for this vulnerability as of June 2014. |
| Related URL |
CVE-2004-1956 (CVE) |
| Related URL |
10191 (SecurityFocus) |
| Related URL |
15933 (ISS) |
|