SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:48
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=107643348117646&w=2 - | |
References | () http://www.scan-associates.net/papers/phpnuke69.txt - | |
References | () http://www.securityfocus.com/bid/9630 - Exploit, Patch, Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/15115 - |
Information
Published : 2004-11-23 05:00
Updated : 2024-11-20 23:48
NVD link : CVE-2004-0269
Mitre link : CVE-2004-0269
CVE.ORG link : CVE-2004-0269
JSON object : View
Products Affected
francisco_burzi
- php-nuke
CWE