PT-2005-2019 · Php · Php-Nuke

Cxib8O3

+1

·

Published

2005-04-07

·

Updated

2016-10-18

·

CVE-2005-0996

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP-Nuke version 7.6
Description The issue concerns SQL injection vulnerabilities in the Downloads module. Remote attackers can inject arbitrary web script or HTML via specific parameters, including the email or url parameters in the Add function, the min parameter in the viewsdownload function, or the min parameter in the search function.
Recommendations For PHP-Nuke version 7.6, consider restricting access to the vulnerable parameters email, url, and min in the affected functions until a patch is available. As a temporary workaround, disabling the Downloads module or limiting its functionality can help minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0996

Affected Products

Php-Nuke