First published: Tue Dec 31 2002(Updated: )
phptonuke.php in myPHPNuke 1.8.8 allows remote attackers to read arbitrary files via a full pathname in the filnavn variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP-Nuke | =1.8.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1913 has a moderate severity level due to its potential for file disclosure.
To mitigate CVE-2002-1913, you should upgrade to a version of myPHPNuke that is not vulnerable, preferably a version later than 1.8.8.
CVE-2002-1913 specifically affects myPHPNuke version 1.8.8.
While CVE-2002-1913 allows remote file reading, it does not directly lead to complete system compromise but could be part of a larger attack.
CVE-2002-1913 is associated with local file inclusion vulnerabilities, allowing attackers to read sensitive files on the server.