PT-2004-2952 · Nucleus · Nucleus Cms

Published

2004-12-31

·

Updated

2017-07-19

·

CVE-2004-2056

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Nucleus CMS version 3.01
Description A SQL injection issue allows remote attackers to execute arbitrary SQL statements. This is achieved by manipulating the itemid parameter in the "action.php" file.
Recommendations For Nucleus CMS version 3.01, consider restricting access to the "action.php" file or avoiding the use of the itemid parameter until a fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2056

Affected Products

Nucleus Cms