CVE-2001-0320
bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument.
- Affected products
- Php-Nuke
- Francisco Burzi Php-nuke
- = 4.0.4, 4.4
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 2.6% (84th percentile)
- NVD status
- Modified
- Published
- 2001-04-04
CVE-2001-0320 at NVD
No indexed exploits for CVE-2001-0320 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2001-0320 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.