HIGH · 7.5

CVE-2004-2044

PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVE...

Vulnerability Description

PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER['PHP_SELF'] to identify the calling script, which allows remote attackers to directly access scripts, obtain path information via a PHP error message, and possibly gain access, as demonstrated using an HTTP request that contains the "admin.php" string.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Francisco BurziPhp-Nuke5.0
OscommerceOsc2Nuke7x_1.0
Paul LaudanskiBetanc Php-Nukebundle
TrustixSecure Linux2.0

References

FAQ

What is CVE-2004-2044?

CVE-2004-2044 is a vulnerability with a CVSS score of 7.5 (HIGH). PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVE...

How severe is CVE-2004-2044?

CVE-2004-2044 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-2044?

Check the references section above for vendor advisories and patch information. Affected products include: Francisco Burzi Php-Nuke, Oscommerce Osc2Nuke, Paul Laudanski Betanc Php-Nuke, Trustix Secure Linux.