Multiple SQL injection vulnerabilities in SergiDs Top Music module 3.0 PR3 and earlier for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the (1) idartist, (2) idsong, and (3) idalbum parameters to modules.php.
Link | Tags |
---|---|
http://pridels0.blogspot.com/2005_11_27_pridels_archive.html | |
http://www.sergids.com/topmusic-changelog.html | |
http://www.securityfocus.com/bid/15581 | vdb entry exploit |
http://www.osvdb.org/21397 | vdb entry exploit |