PHPNuke Search Engine SQL Injection Vulnerability
BID:6887
Info
PHPNuke Search Engine SQL Injection Vulnerability
| Bugtraq ID: | 6887 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 19 2003 12:00AM |
| Updated: | Feb 19 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to: David Zentner <[email protected]>. |
| Vulnerable: |
Francisco Burzi PHP-Nuke 6.0 Francisco Burzi PHP-Nuke 5.6 |
| Not Vulnerable: | |
Discussion
PHPNuke Search Engine SQL Injection Vulnerability
It has been reported that the search module distributed with PHPNuke is vulnerable to an SQL injection attack.
PHPNuke, in some cases, does not sufficiently sanitize user-supplied input which is used when constructing SQL queries. As a result, attackers may supply malicious parameters to manipulate the structure and logic of SQL queries. This may result in unauthorized operations being performed on the underlying database. This issue may be exploited to cause sensitive information to be disclosed to a remote attacker.
It has been reported that the search module distributed with PHPNuke is vulnerable to an SQL injection attack.
PHPNuke, in some cases, does not sufficiently sanitize user-supplied input which is used when constructing SQL queries. As a result, attackers may supply malicious parameters to manipulate the structure and logic of SQL queries. This may result in unauthorized operations being performed on the underlying database. This issue may be exploited to cause sensitive information to be disclosed to a remote attacker.
Exploit / POC
PHPNuke Search Engine SQL Injection Vulnerability
This vulnerability can be exploited using a web browser.
The follow exploit was provided by <[email protected]>:
This vulnerability can be exploited using a web browser.
The follow exploit was provided by <[email protected]>:
Solution / Fix
PHPNuke Search Engine SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHPNuke Search Engine SQL Injection Vulnerability
References:
References:
- PHPNuke INP Homepage (PHPNuke INP)
- PHPNuke SQL Injection - 2003-02-18 (CGI_Shield)