PT-2003-2285 · Php Nuke · Php-Nuke

Bugsman

·

Publicado

2003-12-31

·

Atualizado

2018-10-19

·

CVE-2003-1340

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP-Nuke versions 5.6 and 6.5
Description The issue allows remote authenticated users to execute arbitrary SQL commands via a uid (user) cookie to modules.php. Additionally, remote attackers can execute arbitrary SQL commands via an aid (admin) cookie to the Web Links module in a viewlink, MostPopular, or NewLinksDate action.
Recommendations For PHP-Nuke version 5.6, update to a version that addresses the SQL injection vulnerabilities. For PHP-Nuke version 6.5, update to a version that addresses the SQL injection vulnerabilities. As a temporary workaround, consider restricting access to the modules.php and Web Links module to minimize the risk of exploitation. Avoid using the uid and aid cookies in the affected modules until the issue is resolved.

Exploit

Correção

RCE

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2003-1340

Produtos afetados

Php-Nuke