VulnerabilityModified
CVE-2002-0483
index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that leaks the pathname.
MEDIUM 5.0EPSS 8.24%
Does this matter?
Lower severity and a low EPSS score (8.24%). Track it; it rarely justifies an emergency change on its own.
Description
index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that leaks the pathname.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 8.24% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- francisco burzi/php-nuke
- Source
- cve@mitre.org
References
- http://online.securityfocus.com/archive/1/263337Vendor Advisory
- http://www.iss.net/security_center/static/8618.phpVendor Advisory
- http://www.securityfocus.com/bid/4333Exploit, Vendor Advisory
- http://online.securityfocus.com/archive/1/263337Vendor Advisory
- http://www.iss.net/security_center/static/8618.phpVendor Advisory
- http://www.securityfocus.com/bid/4333Exploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.