Vulnerabilities > CVE-2004-1932 - SQL-Injection vulnerability in PHP-Nuke

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
francisco-burzi
exploit available

Summary

SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter.

Exploit-Db

descriptionPHP-Nuke SQL Injection Edit/Save Message(s) Bug. CVE-2004-1932. Webapps exploit for php platform
idEDB-ID:465
last seen2016-01-31
modified2004-09-16
published2004-09-16
reporteriko94
sourcehttps://www.exploit-db.com/download/465/
titlePHP-Nuke SQL Injection Edit/Save Messages Bug