Vulnerability Name:

CVE-2001-0320 (CCN-6183)

Assigned:2001-02-24
Published:2001-02-24
Updated:2008-09-05
Summary:bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Privileges
References:Source: CCN
Type: BugTraq Mailing List, Tue Feb 13 2001 - 00:59:33 CST
RFP2101: RFPlutonium to fuel your PHP-Nuke

Source: BUGTRAQ
Type: Exploit, Vendor Advisory
20010223 Yet another hole in PHP-Nuke

Source: CCN
Type: BugTraq Mailing List, Fri Feb 23 2001 - 19:44:05 CST
Yet another hole in PHP-Nuke

Source: MITRE
Type: CNA
CVE-2001-0001

Source: MITRE
Type: CNA
CVE-2001-0320

Source: CCN
Type: PHP-Nuke Web site
PHP-Nuke Download Section

Source: CCN
Type: OSVDB ID: 3412
PHP-Nuke bbcode_ref.php Execute Arbitrary Command

Source: CCN
Type: OSVDB ID: 524
PHP-Nuke bb_smilies.php Execute Arbitrary Command

Source: CCN
Type: BID-2422
PHP Nuke User Settings Modification Vulnerability

Source: XF
Type: UNKNOWN
php-nuke-elevate-privileges(6183)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:francisco_burzi:php-nuke:4.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:francisco_burzi:php-nuke:4.4:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:phpnuke:php-nuke:4.4:*:*:*:*:*:*:*
  • OR cpe:/a:phpnuke:php-nuke:4.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    francisco_burzi php-nuke 4.0.4
    francisco_burzi php-nuke 4.4
    phpnuke php-nuke 4.4
    phpnuke php-nuke 4.3