7.5
CVSSv2

CVE-2007-2556

Published: 09/05/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Nuked-klaN 1.7.6 allows remote malicious users to execute arbitrary SQL commands via the X-Forwarded-For (X_FORWARDED_FOR) HTTP header, as demonstrated by a request to the /nk/ URI.

Vulnerable Product Search on Vulmon Subscribe to Product

nuked-klan nuked-klan 1.7.6

Exploits

<?php # # Name: Nuked-klaN <= 177 and <= SP44 Multiple Vulnerabilities Exploit # Credits: Charles FOL <charlesfol[at]hotmailfr> # URL: realo-nfr/ # Date: 14/10/2008 # # Special thanks to Louis for remembering me I had to finish it =) # # VULNERABILITY DETAILS # --------------------- # # Nuked-klaN suffers from ...
<?php # # Nuked-klaN 176 Remote Code Execution Exploit # ------------------------------------------------ # Author: DarkFig <gmdarkfig@gmailcom> # Website: wwwacid-rootnewfr/ # PHP conditions: None =] # Private since 2 months # error_reporting(E_ALL ^ E_NOTICE); # This file require the PhpSploit class $xpl = new phpsploit( ...