PHP-Nuke User/Admin Cookie SQL Injection Vulnerability
BID:7762
Info
PHP-Nuke User/Admin Cookie SQL Injection Vulnerability
| Bugtraq ID: | 7762 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 30 2003 12:00AM |
| Updated: | May 30 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to bugsman <[email protected]>. |
| Vulnerable: |
Francisco Burzi PHP-Nuke 6.5 Francisco Burzi PHP-Nuke 5.6 |
| Not Vulnerable: | |
Discussion
PHP-Nuke User/Admin Cookie SQL Injection Vulnerability
PHP-Nuke, with Web_Links module and one link active, is reported to be prone to SQL injection attacks during authentication. This is due to insufficient sanitization of cookie values, which will be used in database queries. This could permit an attacker to inject SQL code and ultimately disclose admin and user password hashes.
PHP-Nuke, with Web_Links module and one link active, is reported to be prone to SQL injection attacks during authentication. This is due to insufficient sanitization of cookie values, which will be used in database queries. This could permit an attacker to inject SQL code and ultimately disclose admin and user password hashes.
Exploit / POC
PHP-Nuke User/Admin Cookie SQL Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
PHP-Nuke User/Admin Cookie SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHP-Nuke User/Admin Cookie SQL Injection Vulnerability
References:
References:
- PHP-Nuke Product Page (Francisco Burzi)
- PHPNuke INP Homepage (PHPNuke INP)
- Php-Nuke:users_and_admins_password_hashes_vulnerability (bugsman
)