Vulnerabilities > CVE-2007-1061 - SQL Injection vulnerability in PHP-Nuke

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
francisco-burzi
exploit available

Summary

SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" block is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header (HTTP_REFERER variable).

Vulnerable Configurations

Part Description Count
Application
Francisco_Burzi
1

Exploit-Db

descriptionPHP-Nuke <= 8.0 Final (HTTP Referers) Remote SQL Injection Exploit. CVE-2007-1061. Webapps exploit for php platform
fileexploits/php/webapps/3346.pl
idEDB-ID:3346
last seen2016-01-31
modified2007-02-20
platformphp
port
published2007-02-20
reporterkrasza
sourcehttps://www.exploit-db.com/download/3346/
titlePHP-Nuke <= 8.0 Final HTTP Referers Remote SQL Injection Exploit
typewebapps