CVE-2004-1830: Medium severity francisco burzi php-nuke vulnerability
Published Mar 18, 2004
·Updated
error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (3) lang parameter, which leaks the pathname in a PHP error message.
Affected Software
1 affected component
Francisco Burzi PHP-Nuke=6.0
Event History
Mar 18, 2004
CVE Published
05:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1830?
CVE-2004-1830 is classified as a medium severity vulnerability due to its potential to leak sensitive information.
2
How do I fix CVE-2004-1830?
To fix CVE-2004-1830, you should upgrade PHP-Nuke to a version that addresses this vulnerability, preferably above version 6.0.
3
What type of attacks can exploit CVE-2004-1830?
CVE-2004-1830 can be exploited by remote attackers who manipulate certain parameters to reveal sensitive file paths.
4
Which software is affected by CVE-2004-1830?
CVE-2004-1830 affects PHP-Nuke version 6.0 specifically.
5
What information can be leaked through CVE-2004-1830?
CVE-2004-1830 can leak file path information through PHP error messages displayed when invalid parameters are used.