CVE-2000-0745: High severity Francisco Burzi PHP-Nuke vulnerability
admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0745?
CVE-2000-0745 is considered a high-severity vulnerability due to its ability to allow remote attackers to gain unauthorized privileges.
How do I fix CVE-2000-0745?
To fix CVE-2000-0745, ensure that PHP-Nuke is updated to a version that properly verifies administrator credentials.
What software versions are affected by CVE-2000-0745?
CVE-2000-0745 affects PHP-Nuke versions 1.0 and 2.5.
What kind of attack does CVE-2000-0745 allow?
CVE-2000-0745 allows remote attackers to gain administrative privileges by exploiting improper password verification in admin.php3.
Is there a workaround for CVE-2000-0745?
A temporary workaround for CVE-2000-0745 would be to restrict access to the admin.php3 script while awaiting an official patch.