CVE-2004-1956
PostNuke 0.7.2.6 allows remote attackers to gain information via a direct HTTP request to files in the (1) includes/blocks directory, (2) pnadodb directory, (3) NS-NewUser module, (4) NS-Your_Account, (5) NS-LostPassword module, or (6) NS-User module which reveals the path to the web server in a PHP error message.
- Affected products
- Postnuke
- Postnuke Software Foundation Postnuke
- = 0.726
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 1.5% (73th percentile)
- NVD status
- Modified
- Published
- 2005-05-10
CVE-2004-1956 at NVD
No indexed exploits for CVE-2004-1956 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2004-1956 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.