First published: Tue Dec 31 2002(Updated: )
PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and possibly execute code via the caselist parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb | =0.703 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2015 has a high severity rating due to its ability to allow remote file inclusion and potential code execution.
To fix CVE-2002-2015, upgrade PostNuke to a later version where this vulnerability has been patched.
CVE-2002-2015 affects PostNuke version 0.703.
Yes, CVE-2002-2015 can allow remote attackers to include arbitrary files, leading to code execution.
CVE-2002-2015 should not be a concern if PostNuke is updated to a version beyond 0.703, but systems still running the old version are at risk.