CVE-2002-0483: Medium severity Francisco Burzi PHP-Nuke vulnerability
Published Jun 11, 2002
·Updated
index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that leaks the pathname.
Affected Software
7 affected components
Francisco Burzi PHP-Nuke=5.3.1
Francisco Burzi PHP-Nuke=5.1
Francisco Burzi PHP-Nuke=5.0
Francisco Burzi PHP-Nuke=5.4
Francisco Burzi PHP-Nuke=5.2a
Francisco Burzi PHP-Nuke=5.0.1
Francisco Burzi PHP-Nuke=5.2
Event History
Jun 11, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0483?
CVE-2002-0483 has a moderate severity level due to the information disclosure it can cause.
2
How do I fix CVE-2002-0483?
To fix CVE-2002-0483, upgrade PHP-Nuke to version 5.5 or later, which addresses this vulnerability.
3
What systems are affected by CVE-2002-0483?
CVE-2002-0483 affects PHP-Nuke versions 5.0 through 5.4 including earlier versions.
4
What kind of attack does CVE-2002-0483 facilitate?
CVE-2002-0483 facilitates information disclosure attacks by revealing the physical pathname of the web server.
5
Can CVE-2002-0483 be exploited remotely?
Yes, CVE-2002-0483 can be exploited remotely by sending specific requests to the affected PHP-Nuke application.