Vulnerabilities > CVE-2004-2295
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN exploit available
Summary
SQL injection vulnerability in the Reviews module in PHP-Nuke 6.0 to 7.3 allows remote attackers to execute arbitrary SQL commands via the order parameter.
Vulnerable Configurations
Exploit-Db
description | PHP-Nuke 6.x/7.x Reviews Module order Parameter SQL Injection. CVE-2004-2295. Webapps exploit for php platform |
id | EDB-ID:24192 |
last seen | 2016-02-02 |
modified | 2004-06-11 |
published | 2004-06-11 |
reporter | Janek Vind |
source | https://www.exploit-db.com/download/24192/ |
title | PHP-Nuke 6.x/7.x Reviews Module order Parameter SQL Injection |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0310.html
- http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0310.html
- http://secunia.com/advisories/11852
- http://secunia.com/advisories/11852
- http://www.osvdb.org/7000
- http://www.osvdb.org/7000
- http://www.securityfocus.com/archive/1/365865
- http://www.securityfocus.com/archive/1/365865
- http://www.securityfocus.com/bid/10524
- http://www.securityfocus.com/bid/10524
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16407
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16407