{"api_version":"1","generated_at":"2026-07-23T04:33:30+00:00","cve":"CVE-2002-0483","urls":{"html":"https://cve.report/CVE-2002-0483","api":"https://cve.report/api/cve/CVE-2002-0483.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0483","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0483"},"summary":{"title":"CVE-2002-0483","description":"index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that leaks the pathname.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-08-12 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/4333","name":"http://www.securityfocus.com/bid/4333","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"PHP Nuke Error Message Web Root Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.iss.net/security_center/static/8618.php","name":"http://www.iss.net/security_center/static/8618.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"ISS X-Force Database: phpnuke-index-path-disclosure (8618): PHP-Nuke index.php path disclosure","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://online.securityfocus.com/archive/1/263337","name":"http://online.securityfocus.com/archive/1/263337","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SecurityFocus HOME Mailing List: BugTraq","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0483","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0483","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"483","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"francisco_burzi","cpe5":"php-nuke","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"483","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"francisco_burzi","cpe5":"php-nuke","cpe6":"5.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"483","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"francisco_burzi","cpe5":"php-nuke","cpe6":"5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"483","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"francisco_burzi","cpe5":"php-nuke","cpe6":"5.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"483","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"francisco_burzi","cpe5":"php-nuke","cpe6":"5.2a","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"483","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"francisco_burzi","cpe5":"php-nuke","cpe6":"5.3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"483","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"francisco_burzi","cpe5":"php-nuke","cpe6":"5.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:49:28.604Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20020320 Fw: PHPNuke 5.4 Path Disclosure Vulnerability?","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://online.securityfocus.com/archive/1/263337"},{"name":"phpnuke-index-path-disclosure(8618)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/8618.php"},{"name":"4333","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4333"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-03-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that leaks the pathname."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2002-06-15T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20020320 Fw: PHPNuke 5.4 Path Disclosure Vulnerability?","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://online.securityfocus.com/archive/1/263337"},{"name":"phpnuke-index-path-disclosure(8618)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/8618.php"},{"name":"4333","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4333"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0483","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that leaks the pathname."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20020320 Fw: PHPNuke 5.4 Path Disclosure Vulnerability?","refsource":"BUGTRAQ","url":"http://online.securityfocus.com/archive/1/263337"},{"name":"phpnuke-index-path-disclosure(8618)","refsource":"XF","url":"http://www.iss.net/security_center/static/8618.php"},{"name":"4333","refsource":"BID","url":"http://www.securityfocus.com/bid/4333"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0483","datePublished":"2002-06-11T04:00:00.000Z","dateReserved":"2002-06-07T00:00:00.000Z","dateUpdated":"2024-08-08T02:49:28.604Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-08-12 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:francisco_burzi:php-nuke:5.0:*:*:*:*:*:*:*","matchCriteriaId":"93B755A9-694E-49FA-9068-353203AF9965"},{"vulnerable":true,"criteria":"cpe:2.3:a:francisco_burzi:php-nuke:5.0.1:*:*:*:*:*:*:*","matchCriteriaId":"CA0B88AD-CACF-4E48-A4B1-313FFE32D058"},{"vulnerable":true,"criteria":"cpe:2.3:a:francisco_burzi:php-nuke:5.1:*:*:*:*:*:*:*","matchCriteriaId":"FF4C3F85-A23C-40B9-9B0F-564E7C254AA5"},{"vulnerable":true,"criteria":"cpe:2.3:a:francisco_burzi:php-nuke:5.2:*:*:*:*:*:*:*","matchCriteriaId":"4EAF55C4-F0A7-4A36-B203-83670D58483F"},{"vulnerable":true,"criteria":"cpe:2.3:a:francisco_burzi:php-nuke:5.2a:*:*:*:*:*:*:*","matchCriteriaId":"E3ED3BFC-C8CF-4537-832C-0D00400AC064"},{"vulnerable":true,"criteria":"cpe:2.3:a:francisco_burzi:php-nuke:5.3.1:*:*:*:*:*:*:*","matchCriteriaId":"C94B62CA-8D34-4B37-8748-1FE64F0299DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:francisco_burzi:php-nuke:5.4:*:*:*:*:*:*:*","matchCriteriaId":"8720AE61-41C7-4EA8-8C01-81AC0BFACBCC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"483","Ordinal":"1","Title":"CVE-2002-0483","CVE":"CVE-2002-0483","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"483","Ordinal":"1","NoteData":"index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that leaks the pathname.","Type":"Description","Title":"CVE-2002-0483"},{"CveYear":"2002","CveId":"483","Ordinal":"2","NoteData":"2002-06-11","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"483","Ordinal":"3","NoteData":"2002-06-15","Type":"Other","Title":"Modified"}]}}}