vendor:
NSN Script Depository module
by:
KiNgOfThEwOrLd
5.5
CVSS
MEDIUM
Remote Source Disclosure
200
CWE
Product Name: NSN Script Depository module
Affected Version From: 1.0.0
Affected Version To: 1.0.0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
PHP-Nuke NSN Script Depository module <= 1.0.0 Remote Source Disclosure
This exploit allows an attacker to remotely disclose the source code of a PHP-Nuke NSN Script Depository module version 1.0.0 or below. By providing the target URL and the file path, the exploit generates a form that triggers the disclosure of the specified file.
Mitigation:
Upgrade to a patched version of the PHP-Nuke NSN Script Depository module or restrict access to the module.