Vulnerability Name: | CCN-19311 | ||||||
Published: | 2005-02-14 | ||||||
Updated: | 2005-02-14 | ||||||
Summary: | PHP-Nuke could allow a remote attacker to gain elevated privileges, caused by a vulnerability in the admin.php script. A remote attacker could send a specially-crafted POST request to the admin.php script, which would allow the attacker to gain access to the program and obtain elevated privileges. | ||||||
CVSS v3 Severity: | 5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||
CVSS v2 Severity: | 6.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
| ||||||
Vulnerability Consequences: | Gain Privileges | ||||||
References: | Source: CCN Type: PHP-Nuke Web site PHP-Nuke Source: CCN Type: SecuriTeam Mailing List, 14 Feb 2005 PHP-Nuke POST Method Admin Variable Privilege Escalation Source: XF Type: UNKNOWN phpnuke-admin-gain-privilege(19311) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |