Description
PHP-Nuke 5.2 allows remote attackers to copy and delete arbitrary files by calling case.filemanager.php with admin.php as an argument, which sets the $PHP_SELF variable and makes it appear that case.filemanager.php is being called by admin.php instead of the user.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2001-0837 | PHP-Nuke 5.2 allows remote attackers to copy and delete arbitrary files by calling case.filemanager.php with admin.php as an argument, which sets the $PHP_SELF variable and makes it appear that case.filemanager.php is being called by admin.php instead of the user. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T04:37:06.546Z
Reserved: 2001-11-22T00:00:00.000Z
Link: CVE-2001-0854
No data.
Status : Deferred
Published: 2001-12-06T05:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2001-0854
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD