CVE-2004-1937
Last modified
CVE-2004-1937 is a vulnerability of currently unknown severity. Multiple directory traversal vulnerabilities in Nuked-KlaN 1.4b and 1.5b allow remote attackers to read or include arbitrary files via .. sequences in (1) the user_langue parameter to index.php or (2) the langue parameter to update.php, or modify arbitrary GLOBAL variables by causing globals.php to be loaded before conf.inc.php via (3) .. EPSS estimates a 8.12% chance of exploitation in the next 30 days.
Description
Multiple directory traversal vulnerabilities in Nuked-KlaN 1.4b and 1.5b allow remote attackers to read or include arbitrary files via .. sequences in (1) the user_langue parameter to index.php or (2) the langue parameter to update.php, or modify arbitrary GLOBAL variables by causing globals.php to be loaded before conf.inc.php via (3) .. sequences in the file parameter with the page parameter set to globals, or (4) ../globals.php in the user_langue parameter, as demonstrated by modifying $nuked[prefix] in the Suggest module.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nuked-Klan | Nuked-Klan | 1.2 |
| Nuked-Klan | Nuked-Klan | 1.2_beta |
| Nuked-Klan | Nuked-Klan | 1.3 |
| Nuked-Klan | Nuked-Klan | 1.3_beta |
| Nuked-Klan | Nuked-Klan | 1.4 |
| Nuked-Klan | Nuked-Klan | 1.5 |
| Nuked-Klan | Nuked-Klan | 1.5_sp2 |
References
- http://www.phpsecure.info/v2/tutos/frog/Nuked-KlaN.txtExploit, Patch
- http://www.securityfocus.com/bid/10104Exploit, Patch
- http://www.phpsecure.info/v2/tutos/frog/Nuked-KlaN.txtExploit, Patch
- http://www.securityfocus.com/bid/10104Exploit, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-1937?
How severe is CVE-2004-1937?
How do I fix CVE-2004-1937?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-1930Cross-site scripting (XSS) vulnerability in the cookiedecode…
- CVE-2004-1932SQL injection vulnerability in (1) auth.php and (2) admin.ph…
- CVE-2004-1933Citadel/UX 5.00 through 6.14 installs the database directory…
- CVE-2004-1934PHP remote file inclusion vulnerability in affich.php in Gem…
- CVE-2004-1935Cross-site scripting (XSS) vulnerability in SCT Campus Pipel…
- CVE-2004-1936ZoneAlarm Pro 4.5.538.001 and possibly other versions allows…
- CVE-2004-1938SQL injection vulnerability in userlogin.php in Phorum 3.4.7…
- CVE-2004-1939Cross-site scripting (XSS) vulnerability in Zaep AntiSpam 2.…
- CVE-2004-1940sipclient.cpp in KPhone 4.0.1 and earlier allows remote atta…
- CVE-2004-1941Fastream NETFile FTP/Web Server 6.5.1.980 allows remote atta…
- CVE-2004-1942The Solaris 9 patches 113579-02 through 113579-05, and 11434…
- CVE-2004-1943PHP remote file inclusion vulnerability in album_portal.php …
Are you affected by CVE-2004-1937?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
