vendor:
PHP-Nuke
by:
LoSt.HaCkEr
5.5
CVSS
MEDIUM
Remote File Inclusion
98
CWE
Product Name: PHP-Nuke
Affected Version From: 8.1
Affected Version To: 8.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP
2010
PHP-Nuke-8.1-seo-Arabic Remote File Include
The PHP-Nuke-8.1-seo-Arabic script is vulnerable to remote file inclusion. An attacker can exploit this vulnerability by including a malicious file through the 'newlang' parameter in the 'mainfile.php' or the 'ThemeSel' parameter in the 'index.php' file.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of PHP-Nuke or apply necessary security patches.