CVE-2004-0269
Summary
| CVE | CVE-2004-0269 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-11-23 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module. |
Risk And Classification
Primary CVSS: v2.0 6.4 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Francisco Burzi | Php-nuke | 1.0 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 2.5 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 3.0 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 4.0 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 4.3 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 4.4 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 4.4.1a | All | All | All |
| Application | Francisco Burzi | Php-nuke | 5.0 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 5.0.1 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 5.1 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 5.2 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 5.2a | All | All | All |
| Application | Francisco Burzi | Php-nuke | 5.3.1 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 5.4 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 5.5 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 5.6 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 6.0 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 6.5 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 6.5_beta1 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 6.5_final | All | All | All |
| Application | Francisco Burzi | Php-nuke | 6.5_rc1 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 6.5_rc2 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 6.5_rc3 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 6.6 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 6.7 | All | All | All |
| Application | Francisco Burzi | Php-nuke | 6.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| '[SCAN Associates Sdn Bhd Security Advisory] PHPNuke 6.9 > and below SQL Injection in multiple module' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| PHPNuke Category Parameter SQL Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch, Vendor Advisory |
| Home - Scan Associates | af854a3a-2127-422b-91ae-364da2661108 | www.scan-associates.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.