Vulnerabilities > CVE-2003-1210 - Downloads Module SQL Injection vulnerability in PHP-Nuke

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
francisco-burzi
exploit available

Summary

Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to the getit function or the (2) min parameter to the search function.

Exploit-Db

descriptionPHP-Nuke 6.5 Multiple Downloads Module SQL Injection Vulnerabilities. CVE-2003-1210. Webapps exploit for php platform
idEDB-ID:22597
last seen2016-02-02
modified2003-05-13
published2003-05-13
reporterAlbert Puigsech Galicia
sourcehttps://www.exploit-db.com/download/22597/
titlePHP-Nuke 6.5 - Multiple Downloads Module SQL Injection Vulnerabilities