Vulnerability Description
modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) my_headlines, (2) userinfo, or (3) search, which reveals the path in a PHP error message.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Francisco Burzi | Php-Nuke | 6.0 |
References
- http://marc.info/?l=bugtraq&m=111263454308478&w=2
- http://www.securityreason.com/adv/PHPNuke%206.x-7.6-p1.txtExploitPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19953
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44980
- http://marc.info/?l=bugtraq&m=111263454308478&w=2
- http://www.securityreason.com/adv/PHPNuke%206.x-7.6-p1.txtExploitPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19953
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44980
FAQ
What is CVE-2005-1024?
CVE-2005-1024 is a vulnerability with a CVSS score of 5.0 (MEDIUM). modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) my_headlines, (2) userinfo, or (3) search, which reveals the path in a PHP error ...
How severe is CVE-2005-1024?
CVE-2005-1024 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-1024?
Check the references section above for vendor advisories and patch information. Affected products include: Francisco Burzi Php-Nuke.