7.5
CVSSv2

CVE-2002-1242

Published: 12/11/2002 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in PHP-Nuke prior to 6.0 allows remote authenticated users to modify the database and gain privileges via the "bio" argument to modules.php.

Vulnerable Product Search on Vulmon Subscribe to Product

francisco burzi php-nuke 5.6

Exploits

source: wwwsecurityfocuscom/bid/6088/info A SQL injection vulnerability has been reported for PHP-Nuke 56 The vulnerability is due to insufficient sanitization of variables used to construct SQL queries in some scripts It is possible to modify the logic of SQL queries through malformed query strings in requests for the vulnerable scri ...