First published: Wed Dec 31 2003(Updated: )
Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb | <=0.723 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1537 is considered a critical vulnerability due to its potential for remote code execution through directory traversal.
To fix CVE-2003-1537, update PostNuke to version 0.724 or later to eliminate the directory traversal vulnerability.
CVE-2003-1537 affects PostNuke versions 0.723 and earlier.
CVE-2003-1537 allows remote attackers to include arbitrary files through a maliciously crafted theme parameter.
Yes, CVE-2003-1537 can be exploited by unauthenticated attackers, making it particularly dangerous.