First published: Fri Jul 23 2004(Updated: )
The search module in Php-Nuke allows remote attackers to gain sensitive information via the (1) "**" or (2) "+" search patterns, which reveals the path in an error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP-Nuke | =8.0_final |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0736 is classified as a moderate severity vulnerability due to its potential to expose sensitive information.
To mitigate CVE-2004-0736, consider upgrading to a newer, patched version of PHP-Nuke, or implement input validation to sanitize search queries.
CVE-2004-0736 can allow attackers to gain unauthorized access to sensitive paths in the server, potentially leading to further exploitation.
CVE-2004-0736 specifically affects PHP-Nuke version 8.0_final.
As a temporary workaround for CVE-2004-0736, you can disable the search module or restrict search functionality until a patch can be applied.