7.5
CVSSv2

CVE-2003-1435

Published: 31/12/2003 Updated: 29/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote malicious users to execute arbitrary SQL commands via the days parameter to the search module.

Vulnerable Product Search on Vulmon Subscribe to Product

francisco burzi php-nuke 5.6

francisco burzi php-nuke 6.0

Exploits

source: wwwsecurityfocuscom/bid/6887/info It has been reported that the search module distributed with PHPNuke is vulnerable to an SQL injection attack PHPNuke, in some cases, does not sufficiently sanitize user-supplied input which is used when constructing SQL queries As a result, attackers may supply malicious parameters to manipul ...