Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=105276019312980&w=2 | mailing list |
http://www.securityfocus.com/bid/7588 | vdb entry |
http://www.securityfocus.com/bid/7558 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2003-05/0147.html | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/11984 | vdb entry |