vendor:
PHP Nuke
by:
Foster
7.5
CVSS
HIGH
PHP Nuke exploit
89
CWE
Product Name: PHP Nuke
Affected Version From: 6
Affected Version To: 8
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2005
RST/GHC unpublished PHP Nuke exploit <8
This exploit allows an attacker to gain access to the administrative account of a vulnerable PHP Nuke installation. The exploit works by sending a specially crafted HTTP request to the vulnerable server, which then returns the administrative account's password hash. The attacker can then use this hash to gain access to the administrative account.
Mitigation:
Upgrade to the latest version of PHP Nuke, which is not vulnerable to this exploit.