header-logo
Suggest Exploit
vendor:
News Module
by:
SecurityFocus
4.3
CVSS
MEDIUM
Path Disclosure
200
CWE
Product Name: News Module
Affected Version From: PHPNuke 5.5
Affected Version To: PHPNuke 6.0
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002

PHPNuke News Module Path Disclosure Vulnerability

The News module for PHPNuke has been reported prone to a vulnerability which, when exploited, may disclose sensitive path information to a remote attacker. An attacker may use the information gathered in this manner to mount further attacks against the host.

Mitigation:

Ensure that the News module is up to date and that all security patches are applied.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/7079/info

The News module for PHPNuke has been reported prone to a vulnerability which, when exploited, may disclose sensitive path information to a remote attacker.

An attacker may use the information gathered in this manner to mount further attacks against the host.

This vulnerability was reported to affect the News module shipped with PHPNuke version 5.5 and 6.0 it has been suggested that other versions may also be affected.

http://www.example.com/modules.php?name=News&file=print&sid=
http://www.example.com/modules.php?name=News&file=print&sid=[Any_Text]