Vulnerabilities > CVE-2004-2000 - SQL Injection vulnerability in PHP-Nuke Modules.php

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
francisco-burzi
exploit available

Summary

SQL injection vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL via the (1) orderby or (2) sid parameters to modules.php.

Exploit-Db

descriptionPHP-Nuke Downloads Module 'sid' Parameter SQL Injection Vulnerability. CVE-2004-2000. Webapps exploit for php platform
idEDB-ID:31283
last seen2016-02-03
modified2008-02-21
published2008-02-21
reporterS@BUN
sourcehttps://www.exploit-db.com/download/31283/
titlePHP-Nuke Downloads Module - 'sid' Parameter SQL Injection Vulnerability