PT-2004-2827 · Php · Php-Nuke

Published

2004-04-13

·

Updated

2017-07-11

·

CVE-2004-1929

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP-Nuke versions 6.x through 7.2
Description The issue allows remote attackers to bypass authentication and gain access by injecting base64-encoded SQL code into the user parameter in the bblogin function.
Recommendations For PHP-Nuke versions 6.x through 7.2, consider restricting access to the bblogin function until a patch is available. As a temporary workaround, avoid using the user parameter in the affected function to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1929

Affected Products

Php-Nuke