CVE-2003-1210

Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to the getit function or the (2) min parameter to the search function.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:francisco_burzi:php-nuke:*:*:*:*:*:*:*:*
cpe:2.3:a:francisco_burzi:php-nuke:6.5_beta1:*:*:*:*:*:*:*
cpe:2.3:a:francisco_burzi:php-nuke:6.5_final:*:*:*:*:*:*:*
cpe:2.3:a:francisco_burzi:php-nuke:6.5_rc1:*:*:*:*:*:*:*
cpe:2.3:a:francisco_burzi:php-nuke:6.5_rc2:*:*:*:*:*:*:*
cpe:2.3:a:francisco_burzi:php-nuke:6.5_rc3:*:*:*:*:*:*:*

History

20 Nov 2024, 23:46

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2003-05/0147.html - Exploit () http://archives.neohapsis.com/archives/bugtraq/2003-05/0147.html - Exploit
References () http://www.securityfocus.com/bid/7588 - Exploit () http://www.securityfocus.com/bid/7588 - Exploit
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/11984 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/11984 -

Information

Published : 2003-12-31 05:00

Updated : 2024-11-20 23:46


NVD link : CVE-2003-1210

Mitre link : CVE-2003-1210

CVE.ORG link : CVE-2003-1210


JSON object : View

Products Affected

francisco_burzi

  • php-nuke