CVE-2004-2044 - CVE House
Back to Database
Status published High CVE-2004-2044

PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase...

Vulnerability Description

PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER['PHP_SELF'] to identify the calling script, which allows remote attackers to directly access scripts, obtain path information via a PHP error message, and possibly gain access, as demonstrated using an HTTP request that contains the "admin.php" string.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-2044

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

francisco burzi

View all reports →

Affected Software

php-nuke, osc2nuke, betanc php-nuke, secure linux
Vulnerable Versions:
5.0, 5.0.1, 5.1, 5.2, 5.2a, 5.3.1, 5.4, 5.5, 5.6, 6.0, 6.5, 6.5_beta1, 6.5_final, 6.5_rc1, 6.5_rc2, 6.5_rc3, 6.6, 6.7, 6.9, 7.0, 7.0_final, 7.1, 7.2, 7.3, 7x_1.0, bundle, 2.0, 2.1

Timeline

Official Publish: May 10th, 2005
Last Modified: August 8th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.