CVE-2005-1001: Medium severity Francisco Burzi PHP-Nuke vulnerability
Published Apr 7, 2005
·Updated
PHP-Nuke 7.6 allows remote attackers to obtain sensitive information via direct requests to (1) the Surveys module with the file parameter set to comments or (2) 3D-Fantasy/theme.php, which leaks the full pathname of the web server in a PHP error message.
Affected Software
1 affected component
Francisco Burzi PHP-Nuke=7.6
Remediation
Event History
Apr 7, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1001?
CVE-2005-1001 is classified as a medium severity vulnerability.
2
How do I fix CVE-2005-1001?
To fix CVE-2005-1001, you should upgrade PHP-Nuke to the latest version that addresses this vulnerability.
3
What information can attackers obtain from CVE-2005-1001?
Attackers can obtain sensitive information including the full pathname of the web server through specific requests.
4
Which version of PHP-Nuke is affected by CVE-2005-1001?
PHP-Nuke version 7.6 is affected by CVE-2005-1001.
5
Are there any known exploits for CVE-2005-1001?
Yes, there are known exploits that target CVE-2005-1001, allowing attackers to retrieve sensitive server information.