PT-2005-4116 · Unknown · Nuked-Klan

Papipsycho

·

Published

2005-10-25

·

Updated

2017-07-11

·

CVE-2005-3305

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Nuked Klan version 1.7
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via several parameters in different files, including the forum id or thread id parameter in the Forum file, the link id in the Links file, the artid parameter in the Sections file, and the dl id parameter in the Download file.
Recommendations For Nuked Klan version 1.7, consider restricting access to the Forum, Links, Sections, and Download files until a patch is available. As a temporary workaround, avoid using the parameters forum id, thread id, link id, artid, and dl id in their respective files to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3305

Affected Products

Nuked-Klan