The Web_Links module in PHP-Nuke 6.0 through 6.5 final allows remote attackers to obtain the full web server path via an invalid cid parameter that is non-numeric or null, which leaks the pathname in an error message.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2003-12-31 05:00
Updated : 2017-07-29 01:29
NVD link : CVE-2003-1468
Mitre link : CVE-2003-1468
CVE.ORG link : CVE-2003-1468
JSON object : View
Products Affected
                francisco_burzi
- php-nuke
 
CWE
                
                    
                        
                        CWE-200
                        
            Exposure of Sensitive Information to an Unauthorized Actor
