CVE-2001-0320: Critical severity Francisco Burzi PHP-Nuke vulnerability
Published Apr 4, 2001
·Updated
bbsmilies.php and bbcoderef.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument.
Affected Software
2 affected components
Francisco Burzi PHP-Nuke=4.4
Francisco Burzi PHP-Nuke=4.0.4
Event History
Apr 4, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0320?
CVE-2001-0320 is considered a high severity vulnerability due to its potential for remote file access and privilege escalation.
2
How do I fix CVE-2001-0320?
To fix CVE-2001-0320, upgrade PHP-Nuke to version 4.4.1 or later, which addresses this vulnerability.
3
What impact does CVE-2001-0320 have on PHP-Nuke?
CVE-2001-0320 allows remote attackers to read arbitrary files and gain PHP administrator privileges.
4
Which versions of PHP-Nuke are affected by CVE-2001-0320?
CVE-2001-0320 affects PHP-Nuke versions 4.0.4 and 4.4.
5
Who is impacted by CVE-2001-0320?
Any user or organization utilizing PHP-Nuke versions 4.0.4 or 4.4 is at risk from CVE-2001-0320.