vendor:
PHP-Nuke
by:
SecurityFocus
2.6
CVSS
LOW
Path Disclosure
200
CWE
Product Name: PHP-Nuke
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
PHP-Nuke Path Disclosure Vulnerability
A vulnerability has been reported in some versions of PHP-Nuke. Reportedly, a maliciously constructed HTTP request will cause the index.php script to return an error message which includes the full path of the script. It has been suggested that this is the result of an insecure server configuration.
Mitigation:
Ensure that the server is configured securely and that the web server is not revealing the full path of the script.