PHP-Nuke 5.6 Modules.PHP SQL Injection Vulnerability
BID:6088
Info
PHP-Nuke 5.6 Modules.PHP SQL Injection Vulnerability
| Bugtraq ID: | 6088 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1242 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Discovery of this vulnerability credited to kill9 ([email protected]). |
| Vulnerable: |
Francisco Burzi PHP-Nuke 5.6 |
| Not Vulnerable: |
Francisco Burzi PHP-Nuke 6.0 |
Discussion
PHP-Nuke 5.6 Modules.PHP SQL Injection Vulnerability
A SQL injection vulnerability has been reported for PHP-Nuke 5.6.
The vulnerability is due to insufficient sanitization of variables used to construct SQL queries in some scripts. It is possible to modify the logic of SQL queries through malformed query strings in requests for the vulnerable script.
By injecting SQL code into variables, it may be possible for an attacker to corrupt database information.
A SQL injection vulnerability has been reported for PHP-Nuke 5.6.
The vulnerability is due to insufficient sanitization of variables used to construct SQL queries in some scripts. It is possible to modify the logic of SQL queries through malformed query strings in requests for the vulnerable script.
By injecting SQL code into variables, it may be possible for an attacker to corrupt database information.
Exploit / POC
PHP-Nuke 5.6 Modules.PHP SQL Injection Vulnerability
The following proof of concept was provided:
modules.php?name=Your_Account&op=saveuser&uid=2&bio=%5c&EditedMessage=
no&pass=xxxxx&vpass=xxxxx&newsletter=,+bio=0,+pass=md5(1)/*
The following proof of concept was provided:
modules.php?name=Your_Account&op=saveuser&uid=2&bio=%5c&EditedMessage=
no&pass=xxxxx&vpass=xxxxx&newsletter=,+bio=0,+pass=md5(1)/*
Solution / Fix
PHP-Nuke 5.6 Modules.PHP SQL Injection Vulnerability
Solution:
Fixes are available:
Francisco Burzi PHP-Nuke 5.6
Solution:
Fixes are available:
Francisco Burzi PHP-Nuke 5.6
-
Francisco Burzi PHP-Nuke 6.0
http://www.phpnuke.org./modules.php?name=Downloads&d_op=getit&lid=321
References
PHP-Nuke 5.6 Modules.PHP SQL Injection Vulnerability
References:
References: