PHP-Nuke Survey Module SQL Injection Vulnerability
BID:9305
Info
PHP-Nuke Survey Module SQL Injection Vulnerability
| Bugtraq ID: | 9305 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 27 2003 12:00AM |
| Updated: | Dec 27 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to [email protected]. |
| Vulnerable: |
Francisco Burzi PHP-Nuke 7.0 FINAL Francisco Burzi PHP-Nuke 7.0 Francisco Burzi PHP-Nuke 6.7 Francisco Burzi PHP-Nuke 6.6 Francisco Burzi PHP-Nuke 6.5 RC3 Francisco Burzi PHP-Nuke 6.5 RC2 Francisco Burzi PHP-Nuke 6.5 RC1 Francisco Burzi PHP-Nuke 6.5 FINAL Francisco Burzi PHP-Nuke 6.5 BETA 1 Francisco Burzi PHP-Nuke 6.5 Francisco Burzi PHP-Nuke 6.0 |
| Not Vulnerable: | |
Discussion
PHP-Nuke Survey Module SQL Injection Vulnerability
A vulnerability has been reported to exist in the Survey module of PHP-Nuke that may allow a remote attacker to inject malicious SQL syntax into database queries. The source of this issue is insufficient sanitization of user-supplied input.
A malicious user may influence database queries in order to view or modify sensitive information, potentially compromising the software or the database.
A vulnerability has been reported to exist in the Survey module of PHP-Nuke that may allow a remote attacker to inject malicious SQL syntax into database queries. The source of this issue is insufficient sanitization of user-supplied input.
A malicious user may influence database queries in order to view or modify sensitive information, potentially compromising the software or the database.
Exploit / POC
PHP-Nuke Survey Module SQL Injection Vulnerability
The following proof of concept has been provided:
http://www.example.com/php-nuke/modules.php?name=Surveys&pollID=a'[sql_code_here]
The following proof of concept has been provided:
http://www.example.com/php-nuke/modules.php?name=Surveys&pollID=a'[sql_code_here]
Solution / Fix
PHP-Nuke Survey Module SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHP-Nuke Survey Module SQL Injection Vulnerability
References:
References:
- PHP-Nuke Product Page (Francisco Burzi)
- PHPNuke INP Homepage (PHPNuke INP)
- PHP-NUKE 7.0 FINAL (and olders) sql injection ([email protected])