PHP-Nuke vulnerability! Get your fix NOW!
Date: Friday, July 29, 2005 @ 3:11 PM CDT
Topic: Security Advisory


A security issue with PHP-Nuke has been found in admin.php. This issue allows to add GOD admins easily to the admin. Bug reported to us by PeNdEjO (thanks a lot).

I quickly made a fix and chatserv updated the packages. Its recommended that you get Nuke Patched 3.1 as quick as possible to avoid your site being hacked.

This issue does NOT affect NukeSentinel users or users that have a HTTP Authenticate check on their admin.php

Again, thanks to PeNdEjO

Manual fix available here.





This article comes from Nuke Resources
http://www.nukeresources.com

The URL for this story is:
http://www.nukeresources.com/modules.php?name=News&file=article&sid=1202