{"api_version":"1","generated_at":"2026-07-23T04:04:59+00:00","cve":"CVE-2001-1025","urls":{"html":"https://cve.report/CVE-2001-1025","api":"https://cve.report/api/cve/CVE-2001-1025.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2001-1025","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2001-1025"},"summary":{"title":"CVE-2001-1025","description":"PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the \"prefix\" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2001-08-31 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/3149","name":"http://www.securityfocus.com/bid/3149","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"PHP-Nuke Remote SQL Query Manipulation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0019.html","name":"http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0019.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"Neohapsis Archives - VulnWatch - [VulnWatch] 3 phpnuke bugs (2 possibly lead to admin privs) - From steve@securesolutions.org","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2001-1025","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2001-1025","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2001","cve_id":"1025","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"francisco_burzi","cpe5":"php-nuke","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2001","cve_id":"1025","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"francisco_burzi","cpe5":"php-nuke","cpe6":"5.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T04:44:06.627Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"3149","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/3149"},{"name":"20010803 [VulnWatch] 3 phpnuke bugs (2 possibly lead to admin privs)","tags":["mailing-list","x_refsource_VULNWATCH","x_transferred"],"url":"http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0019.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2001-08-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the \"prefix\" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2002-02-06T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"3149","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/3149"},{"name":"20010803 [VulnWatch] 3 phpnuke bugs (2 possibly lead to admin privs)","tags":["mailing-list","x_refsource_VULNWATCH"],"url":"http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0019.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2001-1025","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the \"prefix\" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"3149","refsource":"BID","url":"http://www.securityfocus.com/bid/3149"},{"name":"20010803 [VulnWatch] 3 phpnuke bugs (2 possibly lead to admin privs)","refsource":"VULNWATCH","url":"http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0019.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2001-1025","datePublished":"2002-02-02T05:00:00.000Z","dateReserved":"2002-01-31T00:00:00.000Z","dateUpdated":"2024-08-08T04:44:06.627Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2001-08-31 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:francisco_burzi:php-nuke:5.0:*:*:*:*:*:*:*","matchCriteriaId":"93B755A9-694E-49FA-9068-353203AF9965"},{"vulnerable":true,"criteria":"cpe:2.3:a:francisco_burzi:php-nuke:5.0.1:*:*:*:*:*:*:*","matchCriteriaId":"CA0B88AD-CACF-4E48-A4B1-313FFE32D058"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2001","CveId":"1025","Ordinal":"1","Title":"CVE-2001-1025","CVE":"CVE-2001-1025","Year":"2001"},"notes":[{"CveYear":"2001","CveId":"1025","Ordinal":"1","NoteData":"PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the \"prefix\" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php.","Type":"Description","Title":"CVE-2001-1025"},{"CveYear":"2001","CveId":"1025","Ordinal":"2","NoteData":"2002-02-02","Type":"Other","Title":"Published"},{"CveYear":"2001","CveId":"1025","Ordinal":"3","NoteData":"2002-02-06","Type":"Other","Title":"Modified"}]}}}