20020327 postnuke v 0.7.0.3 remote command executionmailing list
http://archives.neohapsis.com/archives/bugtraq/2002-03/0345.html CVE-2002-2015
PostNuke 0.703 - caselist Arbitrary Module Include
Record summary
CVE-2002-2015 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and possibly execute code via the caselist parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPostNuke 0.703 - caselist Arbitrary Module IncludeExploitDB exploitby pokleyzz sakamaniakaNot analyzed1 file
References
4postnuke-caselist-include-modules(8699)vdb entry
http://www.iss.net/security_center/static/8699.php 4381vdb entry
http://www.securityfocus.com/bid/4381 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-2015