CVE-2004-1998: Medium severity francisco burzi php-nuke vulnerability
Published May 5, 2004
·Updated
The Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to gain sensitive information via an invalid show parameter to modules.php, which reveals the full path in a PHP error message.
Affected Software
9 affected components
Francisco Burzi PHP-Nuke=6.5
Francisco Burzi PHP-Nuke=7.0
Francisco Burzi PHP-Nuke=7.2
Francisco Burzi PHP-Nuke=6.8
Francisco Burzi PHP-Nuke=6.0
Francisco Burzi PHP-Nuke=6.7
Francisco Burzi PHP-Nuke=6.6
Francisco Burzi PHP-Nuke=6.9
Francisco Burzi PHP-Nuke=7.1
Event History
May 5, 2004
CVE Published
04:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability associated with CVE-2004-1998?
CVE-2004-1998 allows remote attackers to gain sensitive information by exploiting an invalid show parameter in the Downloads module of Php-Nuke.
2
What versions of Php-Nuke are affected by CVE-2004-1998?
Versions of Php-Nuke affected by CVE-2004-1998 include 6.0 through 7.2.
3
What severity level is CVE-2004-1998 classified as?
CVE-2004-1998 is classified as a medium severity vulnerability.
4
How can I mitigate the effects of CVE-2004-1998?
To mitigate CVE-2004-1998, users should upgrade to a non-vulnerable version of Php-Nuke.
5
What information can be exposed due to CVE-2004-1998?
The exploitation of CVE-2004-1998 can reveal the full server path through PHP error messages.