CVE-2005-0433: Medium severity Francisco Burzi PHP-Nuke vulnerability
Published Feb 15, 2005
·Updated
Php-Nuke 7.5 allows remote attackers to determine the full path of the web server via invalid or missing arguments to (1) db.php, (2) mainfile.php, (3) Downloads/index.php, or (4) WebLinks/index.php, which lists the path in a PHP error message.
Affected Software
16 affected components
Francisco Burzi PHP-Nuke=6.5_beta1
Francisco Burzi PHP-Nuke=6.5
Francisco Burzi PHP-Nuke=7.0
Francisco Burzi PHP-Nuke=7.2
Francisco Burzi PHP-Nuke=7.0_final
Francisco Burzi PHP-Nuke=6.5_rc2
Francisco Burzi PHP-Nuke=7.3
Francisco Burzi PHP-Nuke=6.5_rc3
Francisco Burzi PHP-Nuke=7.6
Francisco Burzi PHP-Nuke=6.0
Francisco Burzi PHP-Nuke=6.5_final
Francisco Burzi PHP-Nuke=6.7
Francisco Burzi PHP-Nuke=6.6
Francisco Burzi PHP-Nuke=6.9
Francisco Burzi PHP-Nuke=7.1
Francisco Burzi PHP-Nuke=6.5_rc1
Event History
Feb 15, 2005
CVE Published
05:00 AM
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0433?
CVE-2005-0433 has been classified as medium severity due to its potential to allow path disclosure information to an attacker.
2
How do I fix CVE-2005-0433?
To fix CVE-2005-0433, upgrade to the latest version of PHP-Nuke that addresses this vulnerability.
3
What versions are affected by CVE-2005-0433?
CVE-2005-0433 affects PHP-Nuke versions 6.0 through 7.6.
4
What kind of attack can exploit CVE-2005-0433?
CVE-2005-0433 can be exploited by remote attackers to disclose the full path of the web server.
5
Are there any known exploits for CVE-2005-0433?
Yes, there are known exploits that leverage the path disclosure flaw in CVE-2005-0433.