peter bassill · operator
$ cve CVE-2002-0483 JSON

CVE-2002-0483 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 8.2% (pctl 95)

Patch early

A public exploit exists.

Description

index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that leaks the pathname.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS8.25% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2002-08-12
Last modified2026-06-16

Affected (1)

VendorProduct
francisco burziphp-nuke

Public exploits

SourceTitleDate
exploit-dbPHP-Nuke 5.x - Error Message Web Root Disclosure2002-03-21

References

→ the Explorer  ·  watch your stack  ·  NVD