7.5
CVSSv2

CVE-2003-1210

Published: 31/12/2003 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x up to and including 6.5 allow remote malicious users to execute arbitrary SQL commands via the (1) lid parameter to the getit function or the (2) min parameter to the search function.

Vulnerable Product Search on Vulmon Subscribe to Product

francisco burzi php-nuke 6.5_beta1

francisco burzi php-nuke 6.5_final

francisco burzi php-nuke 6.5_rc1

francisco burzi php-nuke

francisco burzi php-nuke 6.5_rc2

francisco burzi php-nuke 6.5_rc3

Exploits

source: wwwsecurityfocuscom/bid/7588/info PHP-Nuke is reportedly prone to multiple SQL injection vulnerabilities in the Downloads module Exploitation could allow for injection of malicious SQL syntax, resulting in modification of SQL query logic or other attacks wwwexamplecom/modulesphp?name=Downloads&d_op=getit&lid= ...