peter bassill · operator
$ cve CVE-2002-2015 JSON

CVE-2002-2015 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 9.5% (pctl 95)

Patch early

A public exploit exists.

Description

PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and possibly execute code via the caselist parameter.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS9.49% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2002-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
postnuke software foundationpostnuke

Public exploits

SourceTitleDate
exploit-dbPostNuke 0.703 - caselist Arbitrary Module Include2002-03-28

References

→ the Explorer  ·  watch your stack  ·  NVD