CVE-2005-1024Burzi Php-nuke vulnerability

14 documents5 sources
Severity
5.0MEDIUMNVD
EPSS
0.1%
top 83.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 2
Latest updateMay 1

Description

modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) my_headlines, (2) userinfo, or (3) search, which reveals the path in a PHP error message.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDfrancisco_burzi/php-nuke18 versions+17

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9v3f-9r8j-jvcj: modules2022-05-01
CVEList
CVE-2005-1024: modules2005-04-09

💥Exploits & PoCs

8
Exploit-DB
TYPSoft FTP Server 1.10 - 'RETR' Denial of Service (2)2010-12-29
Exploit-DB
WinRAR 3.30 - 'Filename' Local Buffer Overflow (1)2006-01-04
Exploit-DB
Snort 2.4.2 - Back Orifice Parsing Remote Buffer Overflow2005-10-25
Exploit-DB
Crob FTP Server 3.6.1 - Remote Stack Overflow2005-06-03
Exploit-DB
Snmppd - SNMP Proxy Daemon Remote Format String2005-04-29

💬Community

3
Bugzilla
CVE-2005-0400 ext2 mkdir() directory entry random kernel memory leak2005-03-29
Bugzilla
CVE-2005-0400 ext2 mkdir() directory entry random kernel memory leak2005-03-29
Bugzilla
CVE-2005-0400 ext2 mkdir() directory entry random kernel memory leak (ipf)2005-03-29
CVE-2005-1024 — Francisco Burzi Php-nuke vulnerability | cvebase