PT-2006-1951 · Php · Php-Nuke
Janek Vind
+1
·
Published
2006-02-28
·
Updated
2018-10-18
·
CVE-2006-0908
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PHP-Nuke version 7.8 Patched 3.2
Description
The issue allows remote attackers to bypass SQL injection protection mechanisms. This can be achieved via /* sequences with the "ad click" word in the query string. For example, this can be demonstrated via the
kala parameter in a request to an API endpoint such as "/%2a".Recommendations
For PHP-Nuke version 7.8 Patched 3.2, consider restricting access to the
kala parameter in the affected API endpoint until a patch is available. As a temporary workaround, avoid using the parameter kala in requests to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Php-Nuke