FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

SQL injection vulnerability in phpnuke

Affected packages
phpnuke <= 6.9

Details

VuXML ID 75770425-67a2-11d8-80e3-0020ed76ef5a
Discovery 2003-12-12
Entry 2004-02-25

Multiple researchers have discovered multiple SQL injection vulnerabilities in some versions of Php-Nuke. These vulnerabilities may lead to information disclosure, compromise of the Php-Nuke site, or compromise of the back-end database.

References

Message http://www.securityfocus.com/archive/1/348375
Message http://www.securityfocus.com/archive/1/353201
URL http://security.nnov.ru/search/document.asp?docid=5748
URL http://www.security-corporation.com/advisories-027.html