PT-2006-1733 · Php · Php-Nuke
Sp3X
·
Published
2006-02-16
·
Updated
2018-10-19
·
CVE-2006-0679
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PHP-Nuke versions 7.8 and earlier
Description
A SQL injection issue allows remote attackers to execute arbitrary SQL commands via the
username variable, specifically in the Nickname field of the Your Account module in index.php.Recommendations
For PHP-Nuke versions 7.8 and earlier, consider restricting access to the Your Account module until a fix is available. As a temporary workaround, avoid using the
username variable in the Nickname field to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Php-Nuke