CVE-2001-0383: Medium severity Francisco Burzi PHP-Nuke vulnerability
Published Jun 18, 2001
·Updated
banners.php in PHP-Nuke 4.4 and earlier allows remote attackers to modify banner ad URLs by directly calling the Change operation, which does not require authentication.
Affected Software
1 affected component
Francisco Burzi PHP-Nuke<=4.4
Event History
Jun 18, 2001
CVE Published
04:00 AM
Sep 18, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0383?
CVE-2001-0383 is classified as a moderate severity vulnerability due to its potential for unauthorized changes to banner ad URLs.
2
How does CVE-2001-0383 affect PHP-Nuke users?
CVE-2001-0383 allows remote attackers to modify banner ad URLs without authentication, posing a risk to system integrity for PHP-Nuke users.
3
How can I fix CVE-2001-0383?
To fix CVE-2001-0383, upgrade to a version of PHP-Nuke later than 4.4 or implement access controls to the banners.php file.
4
What versions of PHP-Nuke are affected by CVE-2001-0383?
CVE-2001-0383 affects PHP-Nuke versions 4.4 and earlier.
5
Is authentication required to exploit CVE-2001-0383?
No, CVE-2001-0383 can be exploited by remote attackers without requiring authentication.