opendir.php script in PHP-Nuke allows remote attackers to read arbitrary files by specifying the filename as an argument to the requesturl parameter.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Php-nuke |
Francisco_burzi |
8.0_final (including) |
8.0_final (including) |
References