PHP-Nuke CVE-2005-1001 Information Disclosure Vulnerability

PHP-Nuke is prone to a information disclosure vulnerability. PHP-Nuke 7.6 allows remote attackers to obtain sensitive information via direct requests to (1) the Surveys module with the file parameter set to comments or (2) 3D-Fantasy/theme.php, which leaks the full pathname of the web server in a PHP error message.


 

Privacy Statement
Copyright 2010, SecurityFocus