Search

published date: November 21, 2001

CVE-2001-0911 : PHP-Nuke 5.1 stores user...

Description

PHP-Nuke 5.1 stores user and administrator passwords in a base-64 encoded cookie, which could allow remote attackers to gain privileges by stealing or sniffing the cookie and decoding it.

Product(s):

  • Francisco Burzi PHP-Nuke 5.1
  • Francisco Burzi PHP-Nuke 5.2
  • Francisco Burzi PHP-Nuke 5.3.1
  • PostNuke 0.64

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2001-0911, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2001-0911 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?