First published: Mon Mar 15 2004(Updated: )
PHP remote file inclusion vulnerability in displaycategory.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary PHP code by modifying the basepath parameter to reference a URL on a remote web server that contains fileFunctions.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Warpspeed 4nalbum Module | =0.92 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1820 has a high severity rating due to its potential for remote code execution.
To fix CVE-2004-1820, update the 4nalbum module to a version that does not utilize the vulnerable 'basepath' parameter.
CVE-2004-1820 affects the 4nalbum module version 0.92 for PHP-Nuke versions 6.5 through 7.0.
CVE-2004-1820 is a remote file inclusion vulnerability that allows attackers to execute arbitrary PHP code.
CVE-2004-1820 can be exploited by remote attackers who can manipulate the 'basepath' parameter.