First published: Thu Mar 18 2004(Updated: )
error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (3) lang parameter, which leaks the pathname in a PHP error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP-Nuke | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1830 is classified as a medium severity vulnerability due to its potential to leak sensitive information.
To fix CVE-2004-1830, you should upgrade PHP-Nuke to a version that addresses this vulnerability, preferably above version 6.0.
CVE-2004-1830 can be exploited by remote attackers who manipulate certain parameters to reveal sensitive file paths.
CVE-2004-1830 affects PHP-Nuke version 6.0 specifically.
CVE-2004-1830 can leak file path information through PHP error messages displayed when invalid parameters are used.