CVE-2004-1820: High severity Warpspeed 4nalbum Module vulnerability
PHP remote file inclusion vulnerability in displaycategory.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary PHP code by modifying the basepath parameter to reference a URL on a remote web server that contains fileFunctions.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1820?
CVE-2004-1820 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2004-1820?
To fix CVE-2004-1820, update the 4nalbum module to a version that does not utilize the vulnerable 'basepath' parameter.
What software is affected by CVE-2004-1820?
CVE-2004-1820 affects the 4nalbum module version 0.92 for PHP-Nuke versions 6.5 through 7.0.
What type of vulnerability is CVE-2004-1820?
CVE-2004-1820 is a remote file inclusion vulnerability that allows attackers to execute arbitrary PHP code.
Who can exploit CVE-2004-1820?
CVE-2004-1820 can be exploited by remote attackers who can manipulate the 'basepath' parameter.