Nucleus CMS Action.PHP SQL Injection Vulnerability
BID:10798
Info
Nucleus CMS Action.PHP SQL Injection Vulnerability
| Bugtraq ID: | 10798 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2004 12:00AM |
| Updated: | Jul 26 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to <[email protected]> . |
| Vulnerable: |
Nucleus CMS Nucleus CMS 3.0 RC Nucleus CMS Nucleus CMS 3.0 1 Nucleus CMS Nucleus CMS 3.0 |
| Not Vulnerable: | |
Discussion
Nucleus CMS Action.PHP SQL Injection Vulnerability
An SQL injection vulnerability is identified in the Nucleus CMS application that may allow attackers to pass malicious input to database queries, resulting in the modification of query logic or other attacks.
This vulnerability exists due to insufficient sanitization of user-supplied input through the 'action.php' script. It may be possible for a remote user to inject arbitrary SQL queries into the underlying database used by the application. This could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.
An SQL injection vulnerability is identified in the Nucleus CMS application that may allow attackers to pass malicious input to database queries, resulting in the modification of query logic or other attacks.
This vulnerability exists due to insufficient sanitization of user-supplied input through the 'action.php' script. It may be possible for a remote user to inject arbitrary SQL queries into the underlying database used by the application. This could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks.
Exploit / POC
Nucleus CMS Action.PHP SQL Injection Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
Nucleus CMS Action.PHP SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Nucleus CMS Action.PHP SQL Injection Vulnerability
References:
References: