PHPNuke News Module Article.PHP SQL Injection Vulnerability
BID:7172
Info
PHPNuke News Module Article.PHP SQL Injection Vulnerability
| Bugtraq ID: | 7172 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 22 2003 12:00AM |
| Updated: | Mar 22 2003 12:00AM |
| Credit: | Discovery credited to "Frog Man" <[email protected]>. |
| Vulnerable: |
Francisco Burzi PHP-Nuke 6.5 RC3 Francisco Burzi PHP-Nuke 6.5 RC2 Francisco Burzi PHP-Nuke 6.5 RC1 Francisco Burzi PHP-Nuke 6.5 Francisco Burzi PHP-Nuke 6.0 Francisco Burzi PHP-Nuke 5.6 |
| Not Vulnerable: | |
Discussion
PHPNuke News Module Article.PHP SQL Injection Vulnerability
It has been reported that an input validation error exists in the article.php file included with PHPNuke as part of the News module. Because of this, an attacker could send a malicious string through PHPNuke that would allow the attacker to manipulate the database, and gain unauthorized access to user accounts.
It has been reported that an input validation error exists in the article.php file included with PHPNuke as part of the News module. Because of this, an attacker could send a malicious string through PHPNuke that would allow the attacker to manipulate the database, and gain unauthorized access to user accounts.
References
PHPNuke News Module Article.PHP SQL Injection Vulnerability
References:
References: