Vulnerabilities > CVE-2004-1912 - Multiple vulnerability in NukeCalendar

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
francisco-burzi
shiba-design
exploit available

Summary

The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke, allow remote attackers to obtain sensitive information via a URL with an invalid argument, which reveals the full path in an error message.

Vulnerable Configurations

Part Description Count
Application
Francisco_Burzi
1
Application
Shiba-Design
1

Exploit-Db

  • descriptionNukeCalendar 1.1 .a block-Calendar.php Path Disclosure. CVE-2004-1912 . Webapps exploit for php platform
    idEDB-ID:23929
    last seen2016-02-02
    modified2004-04-08
    published2004-04-08
    reporterJanek Vind
    sourcehttps://www.exploit-db.com/download/23929/
    titleNukeCalendar 1.1.a - block-Calendar.php Path Disclosure
  • descriptionNukeCalendar 1.1 .a block-Calendar1.php Path Disclosure. CVE-2004-1912. Webapps exploit for php platform
    idEDB-ID:23930
    last seen2016-02-02
    modified2004-04-08
    published2004-04-08
    reporterJanek Vind
    sourcehttps://www.exploit-db.com/download/23930/
    titleNukeCalendar 1.1.a - block-Calendar1.php Path Disclosure
  • descriptionNukeCalendar 1.1 .a block-Calendar_center.php Path Disclosure. CVE-2004-1912. Webapps exploit for php platform
    idEDB-ID:23931
    last seen2016-02-02
    modified2004-04-08
    published2004-04-08
    reporterJanek Vind
    sourcehttps://www.exploit-db.com/download/23931/
    titleNukeCalendar 1.1.a - block-Calendar_center.php Path Disclosure
  • descriptionNukeCalendar 1.1 .a modules.php Path Disclosure. CVE-2004-1912. Webapps exploit for php platform
    idEDB-ID:23928
    last seen2016-02-02
    modified2004-04-08
    published2004-04-08
    reporterJanek Vind
    sourcehttps://www.exploit-db.com/download/23928/
    titleNukeCalendar 1.1.a - modules.php Path Disclosure