First published: Mon Jun 18 2001(Updated: )
banners.php in PHP-Nuke 4.4 and earlier allows remote attackers to modify banner ad URLs by directly calling the Change operation, which does not require authentication.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP-Nuke | <=4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0383 is classified as a moderate severity vulnerability due to its potential for unauthorized changes to banner ad URLs.
CVE-2001-0383 allows remote attackers to modify banner ad URLs without authentication, posing a risk to system integrity for PHP-Nuke users.
To fix CVE-2001-0383, upgrade to a version of PHP-Nuke later than 4.4 or implement access controls to the banners.php file.
CVE-2001-0383 affects PHP-Nuke versions 4.4 and earlier.
No, CVE-2001-0383 can be exploited by remote attackers without requiring authentication.