10
CVSSv2

CVE-2001-1025

Published: 31/08/2001 Updated: 05/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

PHP-Nuke 5.x allows remote malicious users to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php.

Vulnerable Product Search on Vulmon Subscribe to Product

francisco burzi php-nuke 5.0

francisco burzi php-nuke 5.0.1