Total vulnerabilities in the database
The Web_Links module in PHP-Nuke 6.0 through 6.5 final allows remote attackers to obtain the full web server path via an invalid cid parameter that is non-numeric or null, which leaks the pathname in an error message.
Software | From | Fixed in |
---|---|---|
francisco_burzi / php-nuke | 6.5_beta1 | 6.5_beta1.x |
francisco_burzi / php-nuke | 6.5 | 6.5.x |
francisco_burzi / php-nuke | 6.5_rc2 | 6.5_rc2.x |
francisco_burzi / php-nuke | 6.5_rc3 | 6.5_rc3.x |
francisco_burzi / php-nuke | 6.0 | 6.0.x |
francisco_burzi / php-nuke | 6.5_final | 6.5_final.x |
francisco_burzi / php-nuke | 6.5_rc1 | 6.5_rc1.x |