HTTP: PHP-Nuke ViewAdmin Page Unauthorized Access

This signature detects attempts to make changes to the PHP-Nuke database. Attackers can make changes to the database by exploiting a vulnerability in the way PHP-Nuke parses certain HTTP POST requests to admin.php.

Extended Description

Successful exploitation of this vulnerability would allow attackers to elevate their privilege to Superuser level. Once this is achieved, the entire PHP-Nuke system could be compromised by an attacker modifying configuration details, modifying or deleting user accounts, or defacing content.

Short Name
HTTP:PHP:PHPNUKE:VIEWADMIN
Severity
Warning
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Access CVE-2004-1932 PHP-Nuke Page Unauthorized ViewAdmin
Release Date
09/08/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown
CVSS Score

7.5

Found a potential security threat?