PT-2005-2019 · Php · Php-Nuke
Cxib8O3
+1
·
Published
2005-04-07
·
Updated
2016-10-18
·
CVE-2005-0996
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
PHP-Nuke version 7.6
Description
The issue concerns SQL injection vulnerabilities in the Downloads module. Remote attackers can inject arbitrary web script or HTML via specific parameters, including the
email or url parameters in the Add function, the min parameter in the viewsdownload function, or the min parameter in the search function.Recommendations
For PHP-Nuke version 7.6, consider restricting access to the vulnerable parameters
email, url, and min in the affected functions until a patch is available. As a temporary workaround, disabling the Downloads module or limiting its functionality can help minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Php-Nuke