Loading...
Loading...
PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER['PHP_SELF'] to identify the calling script, which allows remote attackers to directly access scripts, obtain path information via a PHP error message, and possibly gain access, as demonstrated using an HTTP request that contains the "admin.php" string.
June 1, 2004
April 16, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2004-2044
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.