Vulnerability Details CVE-2005-1028
PHP-Nuke 6.x through 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) index.php with the forum_admin parameter set, (2) the Surveys module, or (3) the Your_Account module, which reveals the path in a PHP error message.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 56.5%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2005-1028
-
cpe:2.3:a:phpnuke:php-nuke:6.0
-
cpe:2.3:a:phpnuke:php-nuke:6.5
-
cpe:2.3:a:phpnuke:php-nuke:6.6
-
cpe:2.3:a:phpnuke:php-nuke:6.7
-
cpe:2.3:a:phpnuke:php-nuke:6.8
-
cpe:2.3:a:phpnuke:php-nuke:6.9
-
cpe:2.3:a:phpnuke:php-nuke:7.0
-
cpe:2.3:a:phpnuke:php-nuke:7.1
-
cpe:2.3:a:phpnuke:php-nuke:7.2
-
cpe:2.3:a:phpnuke:php-nuke:7.3
-
cpe:2.3:a:phpnuke:php-nuke:7.4
-
cpe:2.3:a:phpnuke:php-nuke:7.5
-
cpe:2.3:a:phpnuke:php-nuke:7.6