PHPNuke Modules.PHP SQL Injection Vulnerability
BID:5799
Info
PHPNuke Modules.PHP SQL Injection Vulnerability
| Bugtraq ID: | 5799 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2002 12:00AM |
| Updated: | Sep 25 2002 12:00AM |
| Credit: | Discovery credited to Pedro Inacio. |
| Vulnerable: |
Francisco Burzi PHP-Nuke 6.0 |
| Not Vulnerable: | |
Discussion
PHPNuke Modules.PHP SQL Injection Vulnerability
A SQL injection vulnerability has been discovered in PHPNuke.
Due to insufficient sanitization of variables used in SQL queries, it is possible to modify the logic of SQL queries.
This issue could result in a denial of service attack or the corruption of database information.
This issue was reported in PHPNuke version 6.0. Other versions may also be affected.
A SQL injection vulnerability has been discovered in PHPNuke.
Due to insufficient sanitization of variables used in SQL queries, it is possible to modify the logic of SQL queries.
This issue could result in a denial of service attack or the corruption of database information.
This issue was reported in PHPNuke version 6.0. Other versions may also be affected.
Exploit / POC
PHPNuke Modules.PHP SQL Injection Vulnerability
No exploit is required.
The following proof will cause a denial of service, and was supplied by Pedro Inacio <[email protected]>.
http://www.nukesite.com/modules.php?name=News&file=article&sid=1234%20or%
201=1
No exploit is required.
The following proof will cause a denial of service, and was supplied by Pedro Inacio <[email protected]>.
http://www.nukesite.com/modules.php?name=News&file=article&sid=1234%20or%
201=1
Solution / Fix
PHPNuke Modules.PHP SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHPNuke Modules.PHP SQL Injection Vulnerability
References:
References: