CVE-2004-2018: High severity Francisco Burzi PHP-Nuke vulnerability
PHP remote file inclusion vulnerability in index.php in Php-Nuke 6.x through 7.3 allows remote attackers to execute arbitrary PHP code by modifying the modpath parameter to reference a URL on a remote web server that contains the code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2018?
CVE-2004-2018 is considered a critical vulnerability as it allows remote attackers to execute arbitrary PHP code.
How do I fix CVE-2004-2018?
To fix CVE-2004-2018, upgrade to a patched version of PHP-Nuke that is not vulnerable, such as versions newer than 7.3.
Which versions of PHP-Nuke are affected by CVE-2004-2018?
CVE-2004-2018 affects PHP-Nuke versions 6.x through 7.3, including specific releases like 6.5, 7.0, and 7.3.
What can attackers do if CVE-2004-2018 is exploited?
If CVE-2004-2018 is exploited, attackers can run unauthorized PHP scripts, potentially compromising the web server.
Is there a workaround for CVE-2004-2018 if I cannot update immediately?
As a workaround for CVE-2004-2018, restrict access to the index.php file and minimize the usage of remote file inclusions.