PT-2004-1818 · Php Nuke · Php-Nuke

Published

2004-07-23

·

Updated

2017-07-11

·

CVE-2004-0738

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Php-Nuke (affected versions not specified)
Description The issue concerns multiple SQL injection vulnerabilities in the Search module of Php-Nuke. These vulnerabilities allow remote attackers to execute arbitrary SQL commands by manipulating the min or categ parameters.
Recommendations For Php-Nuke, consider restricting access to the Search module until a fix is available. As a temporary workaround, avoid using the min and categ parameters in the Search module to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0738

Affected Products

Php-Nuke