PT-2014-5614 · Php Nuke · Php-Nuke

Published

2014-06-02

·

Updated

2014-06-03

·

CVE-2014-3934

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP-Nuke version 8.3
Description A SQL injection issue exists, allowing remote attackers to execute arbitrary SQL commands. This is achieved by exploiting the topics[] parameter in the "modules.php" endpoint, specifically within the Submit News module.
Recommendations For PHP-Nuke version 8.3, consider restricting access to the Submit News module until a patch is available, and avoid using the topics[] parameter in the modules.php endpoint to minimize the risk of exploitation.

Exploit

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3934

Affected Products

Php-Nuke