Low

CVE-2003-0279 - Unspecified vulnerability in Francisco Burzi PHP-Nuke

Publication: 2003-06-16
Summary

Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php.

Risk level (CVSS 2.6)

Low

2.6

Access Vector

  • Network
  • Adjacent Network
  • Local

Access Complexity

  • Low
  • Medium
  • High

Authentication

  • None
  • Single
  • Multiple

Confident. Impact

  • Complete
  • Partial
  • None

Integrity Impact

  • Complete
  • Partial
  • None

Affected Products

  • Francisco Burzi PHP-nuke 5.0
  • Francisco Burzi PHP-nuke 6.0