7.5
CVSSv2

CVE-2007-1034

Published: 21/02/2007 Updated: 19/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and previous versions module for PHP-Nuke allows remote malicious users to execute arbitrary SQL commands via the category_id parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php-nuke emporium module

Exploits

||| PHP-Nuke Module Emporium 230 (id_catg) SQL Injection Vulnerability || Author: Hussin X || Home : WwWIQ-TYCoM<WwWIQ-TYCoM> || email: darkangel_g85[at]Yahoo[DoT]com ||| DorK : inurl:modulesphp?name=Shopping_Cart ||| more Module's Name: Emporium Module's Version: 230 Module's Description: eCommerce for PHP-Nuke ...
<% ResponseBuffer = True %> <% On Error Resume Next %> <% ServerScriptTimeout = 100 %> <% '=============================================================================================== '[Script Name: Php-Nuke Module Emporium <= 230 Remote Blind SQL Injection Exploit '[Coded by : ajann '[Author : ajann '[Contact ...