CVE-2003-1468: Infoleak
The WebLinks module in PHP-Nuke 6.0 through 6.5 final allows remote attackers to obtain the full web server path via an invalid cid parameter that is non-numeric or null, which leaks the pathname in an error message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1468?
CVE-2003-1468 is classified as a medium severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2003-1468?
To fix CVE-2003-1468, upgrade PHP-Nuke to version 6.5 final or later, which addresses this vulnerability.
What does CVE-2003-1468 exploit?
CVE-2003-1468 exploits a weakness in the Web_Links module of PHP-Nuke, allowing attackers to expose the server path via improper parameter handling.
Which versions of PHP-Nuke are affected by CVE-2003-1468?
CVE-2003-1468 affects PHP-Nuke versions 6.0 through 6.5 final, including beta and release candidates.
Can CVE-2003-1468 be exploited remotely?
Yes, CVE-2003-1468 can be exploited remotely by sending crafted requests to the web server.