opendir.php script in PHP-Nuke allows remote attackers to read arbitrary files by specifying the filename as an argument to the requesturl parameter.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Php-nuke | Francisco_burzi | 8.0_final (including) | 8.0_final (including) |
References