PHP-Nuke Multiple Downloads Module SQL Injection Vulnerabilities
BID:7588
Info
PHP-Nuke Multiple Downloads Module SQL Injection Vulnerabilities
| Bugtraq ID: | 7588 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 13 2003 12:00AM |
| Updated: | May 13 2003 12:00AM |
| Credit: | Discovery is credited to Albert Puigsech Galicia <[email protected]>. |
| Vulnerable: |
Francisco Burzi PHP-Nuke 6.5 RC3 Francisco Burzi PHP-Nuke 6.5 RC2 Francisco Burzi PHP-Nuke 6.5 RC1 Francisco Burzi PHP-Nuke 6.5 FINAL Francisco Burzi PHP-Nuke 6.5 BETA 1 Francisco Burzi PHP-Nuke 6.5 |
| Not Vulnerable: | |
Discussion
PHP-Nuke Multiple Downloads Module SQL Injection Vulnerabilities
PHP-Nuke is reportedly prone to multiple SQL injection vulnerabilities in the Downloads module. Exploitation could allow for injection of malicious SQL syntax, resulting in modification of SQL query logic or other attacks.
PHP-Nuke is reportedly prone to multiple SQL injection vulnerabilities in the Downloads module. Exploitation could allow for injection of malicious SQL syntax, resulting in modification of SQL query logic or other attacks.
Solution / Fix
PHP-Nuke Multiple Downloads Module SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHP-Nuke Multiple Downloads Module SQL Injection Vulnerabilities
References:
References:
- PHPNuke INP Homepage (PHPNuke INP)
- More and More SQL injection on PHP-Nuke 6.5. (Albert Puigsech Galicia
)