CVE-2001-1032Burzi Php-nuke vulnerability

4 documents4 sources
Severity
7.5HIGHNVD
EPSS
23.2%
top 4.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 24
Latest updateApr 30

Description

admin.php in PHP-Nuke 5.2 and earlier, except 5.0RC1, does not check login credentials for upload operations, which allows remote attackers to copy and upload arbitrary files and read the PHP-Nuke configuration file by directly calling admin.php with an upload parameter and specifying the file to copy.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-r3rq-wp38-7h2h: admin2022-04-30
CVEList
CVE-2001-1032: admin2002-06-25

💥Exploits & PoCs

1
Exploit-DB
kosch suid wrapper 1.1.1 - Local Buffer Overflow2001-06-07
CVE-2001-1032 — Francisco Burzi Php-nuke vulnerability | cvebase