Directory traversal vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php-nuke | Phpnuke | 7.0 (including) | 7.0 (including) |
Php-nuke | Phpnuke | 7.1 (including) | 7.1 (including) |
Php-nuke | Phpnuke | 7.2 (including) | 7.2 (including) |
Php-nuke | Phpnuke | 7.3 (including) | 7.3 (including) |
Php-nuke | Phpnuke | 7.4 (including) | 7.4 (including) |
Php-nuke | Phpnuke | 7.5 (including) | 7.5 (including) |
Php-nuke | Phpnuke | 7.6 (including) | 7.6 (including) |
Php-nuke | Phpnuke | 7.7 (including) | 7.7 (including) |
Php-nuke | Phpnuke | 7.8 (including) | 7.8 (including) |
Php-nuke | Phpnuke | 7.9 (including) | 7.9 (including) |
Php-nuke | Phpnuke | 8.0 (including) | 8.0 (including) |
Php-nuke | Phpnuke | 8.0.0-final (including) | 8.0.0-final (including) |