|
PHP-Nuke Direct Script Access Restriction Bypass Weakness
|
|
Secunia Advisory:
|
SA11766
|
|
|
Release Date:
|
2004-06-04
|
|
Popularity:
|
10,152 views
|
|
|
Critical:
|
 Not critical
|
|
Impact:
|
Security Bypass
|
|
Where:
|
From remote
|
|
Solution Status:
|
Partial Fix
|
|
| Software: | osc2nuke 7.x oscnukelite 3.x PHP-Nuke 5.x PHP-Nuke 6.x PHP-Nuke 7.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
Description: Squid has reported a weakness in PHP-Nuke, which can be exploited by malicious people to bypass certain security restrictions.
The problem is that PHP-Nuke and multiple modules utilise an insufficient security check to prevent scripts from being accessed directly. This can be exploited via a specially crafted URL and may disclose path information and possibly (depending on the scripts) grant access to restricted resources.
The problem has been reported in the following products:
* PHP-Nuke 7.3 and prior
* Nuke Cops betaNC PHP-Nuke Bundle w/ PHPNuke 6.5 and later
* osc2nuke 7x version 1
* oscnukelite 3.1 and prior
Solution: Patches for some of the issues have reportedly been released.
Provided and/or discovered by: Squid
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|