PHPNuke Remote Main Modules Multiple SQL Injection Vulnerabilities
BID:7631
Info
PHPNuke Remote Main Modules Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 7631 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 20 2003 12:00AM |
| Updated: | May 20 2003 12:00AM |
| Credit: | Discovery credited to Lorenzo Manuel Hernandez Garcia-Hierro <[email protected]>. |
| Vulnerable: |
Francisco Burzi PHP-Nuke 6.5 RC3 Francisco Burzi PHP-Nuke 6.5 RC2 Francisco Burzi PHP-Nuke 6.5 RC1 Francisco Burzi PHP-Nuke 6.5 FINAL Francisco Burzi PHP-Nuke 6.5 BETA 1 Francisco Burzi PHP-Nuke 6.5 Francisco Burzi PHP-Nuke 6.0 Francisco Burzi PHP-Nuke 5.6 Francisco Burzi PHP-Nuke 5.5 Francisco Burzi PHP-Nuke 5.4 Francisco Burzi PHP-Nuke 5.3.1 Francisco Burzi PHP-Nuke 5.2 a Francisco Burzi PHP-Nuke 5.2 Francisco Burzi PHP-Nuke 5.1 Francisco Burzi PHP-Nuke 5.0.1 Francisco Burzi PHP-Nuke 5.0 |
| Not Vulnerable: | |
Discussion
PHPNuke Remote Main Modules Multiple SQL Injection Vulnerabilities
It has been reported that multiple problems exist in the PHPNuke main modules. SQL injection issues exist in the Sections, Avantgo, Surveys, Downloads, Reviews, and Web_Links modules. This could allow an attacker pass malicious SQL code to the database. It should be noted that multiple path disclosure issues also exist.
It has been reported that multiple problems exist in the PHPNuke main modules. SQL injection issues exist in the Sections, Avantgo, Surveys, Downloads, Reviews, and Web_Links modules. This could allow an attacker pass malicious SQL code to the database. It should be noted that multiple path disclosure issues also exist.
Exploit / POC
PHPNuke Remote Main Modules Multiple SQL Injection Vulnerabilities
No exploit is required for this vulnerability. Several proofs-of-concept have been made available by
Lorenzo Manuel Hernandez Garcia-Hierro <[email protected]>. See referenced advisory.
No exploit is required for this vulnerability. Several proofs-of-concept have been made available by
Lorenzo Manuel Hernandez Garcia-Hierro <[email protected]>. See referenced advisory.
Solution / Fix
PHPNuke Remote Main Modules Multiple SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHPNuke Remote Main Modules Multiple SQL Injection Vulnerabilities
References:
References:
- PHPNuke INP Homepage (PHPNuke INP)
- PHP-Nuke Denial of Service attack and more SQL Injections (Lorenzo Manuel Hernandez Garcia-Hierro
) - PHPNuke 6.9 > and below SQL Injection in multiple module (pokley
)