admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php-nuke | Francisco_burzi | 1.0 (including) | 1.0 (including) |
Php-nuke | Francisco_burzi | 2.5 (including) | 2.5 (including) |