Vulnerabilities > CVE-2002-2015 - Unspecified vulnerability in Postnuke Software Foundation Postnuke 0.703

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
postnuke-software-foundation
exploit available

Summary

PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and possibly execute code via the caselist parameter.

Vulnerable Configurations

Part Description Count
Application
Postnuke_Software_Foundation
1

Exploit-Db

descriptionPostNuke 0.703 caselist Arbitrary Module Include Vulnerability. CVE-2002-2015. Webapps exploit for php platform
idEDB-ID:21357
last seen2016-02-02
modified2002-03-28
published2002-03-28
reporterpokleyzz sakamaniaka
sourcehttps://www.exploit-db.com/download/21357/
titlePostNuke 0.703 caselist Arbitrary Module Include Vulnerability