CVE-2005-1024 Information

Description

modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) my_headlines (2) userinfo or (3) search which reveals the path in a PHP error message.

Reference

http://marc.info/?l=bugtraq&m=111263454308478&w=2 http://www.securityreason.com/adv/PHPNuke206.x-7.6-p1.txt https://exchange.xforce.ibmcloud.com/vulnerabilities/19953 https://exchange.xforce.ibmcloud.com/vulnerabilities/44980

Share on: