Multiple PHP-Nuke Forums/Private_Messages SQL Injection Vulnerabilities
BID:7060
Info
Multiple PHP-Nuke Forums/Private_Messages SQL Injection Vulnerabilities
| Bugtraq ID: | 7060 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2003 12:00AM |
| Updated: | Mar 10 2003 12:00AM |
| Credit: | Discovery of these issues is credited to "Frog Man" <[email protected]>. |
| Vulnerable: |
Francisco Burzi PHP-Nuke 6.5 RC2 Francisco Burzi PHP-Nuke 6.0 |
| Not Vulnerable: | |
Discussion
Multiple PHP-Nuke Forums/Private_Messages SQL Injection Vulnerabilities
Multiple SQL injection vulnerabilities were reported in the Forums scripts and 'Private_Messages' module of PHP-Nuke. This is due to insufficient sanitization of externally supplied data which is used to construct SQL queries. A remote attacker may take advantage of these issues to inject malicious data into SQL queries, possibly resulting in modification of query logic. This may be exploited to compromise the PHP-Nuke web portal. Other attacks are also possible.
Multiple SQL injection vulnerabilities were reported in the Forums scripts and 'Private_Messages' module of PHP-Nuke. This is due to insufficient sanitization of externally supplied data which is used to construct SQL queries. A remote attacker may take advantage of these issues to inject malicious data into SQL queries, possibly resulting in modification of query logic. This may be exploited to compromise the PHP-Nuke web portal. Other attacks are also possible.
Exploit / POC
Multiple PHP-Nuke Forums/Private_Messages SQL Injection Vulnerabilities
There is no exploit required.
There is no exploit required.