Multiple SQL injection vulnerabilities in modules.php in PHP-Nuke 7.8, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) sid, and (3) pid parameters in a POST request, which bypasses security checks that are performed for GET requests.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2005-09/0226.html | mailing list |
http://secunia.com/advisories/16801 | patch vendor advisory third party advisory |
http://securityreason.com/securityalert/3 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/22247 | vdb entry |
http://www.nukefixes.com/ftopict-1779-.html#7641 | patch |
http://phpnuke.org/modules.php?name=News&file=article&sid=7434 | patch |
http://www.osvdb.org/19351 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2005-09/0176.html | mailing list |
http://archives.neohapsis.com/archives/bugtraq/2005-09/0119.html | vendor advisory mailing list exploit |
http://archives.neohapsis.com/archives/bugtraq/2005-09/0167.html | mailing list |