PT-2004-2952 · Nucleus · Nucleus Cms
Published
2004-12-31
·
Updated
2017-07-19
·
CVE-2004-2056
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Nucleus CMS version 3.01
Description
A SQL injection issue allows remote attackers to execute arbitrary SQL statements. This is achieved by manipulating the
itemid parameter in the "action.php" file.Recommendations
For Nucleus CMS version 3.01, consider restricting access to the "action.php" file or avoiding the use of the
itemid parameter until a fix is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nucleus Cms