CVE-2001-0854

PHP-Nuke 5.2 allows remote attackers to copy and delete arbitrary files by calling case.filemanager.php with admin.php as an argument, which sets the $PHP_SELF variable and makes it appear that case.filemanager.php is being called by admin.php instead of the user.

Scoring

CVSS base score
0
EPSS probability
0.02%
Published
2001-11-22
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs