First published: Wed Dec 31 2003(Updated: )
PHP-Nuke 7.0 allows remote attackers to obtain the installation path via certain characters such as (1) ", (2) ', or (3) > in the search field, which reveals the path in an error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP-Nuke | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2003-1526 is classified as medium due to the potential for information disclosure.
To fix CVE-2003-1526, update PHP-Nuke to a version higher than 7.0 where this vulnerability is resolved.
CVE-2003-1526 describes an information disclosure vulnerability that allows attackers to reveal the installation path of PHP-Nuke.
CVE-2003-1526 specifically affects PHP-Nuke version 7.0.
Attackers can obtain sensitive installation path information via crafted input in the search field of PHP-Nuke.