PT-2006-1951 · Php · Php-Nuke

Janek Vind

+1

·

Published

2006-02-28

·

Updated

2018-10-18

·

CVE-2006-0908

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP-Nuke version 7.8 Patched 3.2
Description The issue allows remote attackers to bypass SQL injection protection mechanisms. This can be achieved via /* sequences with the "ad click" word in the query string. For example, this can be demonstrated via the kala parameter in a request to an API endpoint such as "/%2a".
Recommendations For PHP-Nuke version 7.8 Patched 3.2, consider restricting access to the kala parameter in the affected API endpoint until a patch is available. As a temporary workaround, avoid using the parameter kala in requests to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0908

Affected Products

Php-Nuke