vendor:
PostNuke
by:
SecurityFocus
7.5
CVSS
HIGH
Arbitrary Module Inclusion
94
CWE
Product Name: PostNuke
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Unix
2002
PostNuke Arbitrary Module Inclusion Vulnerability
A vulnerability has been reported in some versions of PostNuke. Reportedly, it is possible to force the script user.php to include arbitrary modules. These files may be hosted remotely and contain arbitrary code, which will then be executed by the vulnerable system.
Mitigation:
Ensure that the user.php script is not accessible from the web, or that it is not vulnerable to arbitrary module inclusion.