CVE-2002-0483

PHP-Nuke <= 5.4 - Path Disclosure via File Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0483. PoCs published by godminus.

AI-analyzed exploit summary The provided text describes a path disclosure vulnerability in PHP-Nuke, where a maliciously crafted HTTP request causes the index.php script to return an error message containing the full path of the script. This is due to an insecure server configuration.

Description

index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that leaks the pathname.

Exploits (1)

exploitdb WRITEUP VERIFIED
by godminus · textwebappsphp
https://www.exploit-db.com/exploits/21349

The provided text describes a path disclosure vulnerability in PHP-Nuke, where a maliciously crafted HTTP request causes the index.php script to return an error message containing the full path of the script. This is due to an insecure server configuration.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: PHP-Nuke (unspecified version)
No auth needed
Prerequisites: Access to the target web server
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/263337
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/8618.php
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4333

Scores

EPSS 0.0824
EPSS Percentile 94.3%

Details

Status published
Products (7)
francisco_burzi/php-nuke 5.0
francisco_burzi/php-nuke 5.0.1
francisco_burzi/php-nuke 5.1
francisco_burzi/php-nuke 5.2
francisco_burzi/php-nuke 5.2a
francisco_burzi/php-nuke 5.3.1
francisco_burzi/php-nuke 5.4
Published Aug 12, 2002
Tracked Since Feb 18, 2026