Vulnerability Name: | CVE-2001-1025 (CCN-6945) | ||||||||
Assigned: | 2001-08-03 | ||||||||
Published: | 2001-08-03 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Fri Aug 03 2001 - 14:47:04 CDT 3 phpnuke bugs (2 possibly lead to admin privs) Source: VULNWATCH Type: Exploit, Vendor Advisory 20010803 [VulnWatch] 3 phpnuke bugs (2 possibly lead to admin privs) Source: MITRE Type: CNA CVE-2001-1025 Source: CCN Type: PHP-Nuke Web site PHP-Nuke Source: CCN Type: OSVDB ID: 6239 PHP-Nuke article.php Arbitrary SQL Query Source: CCN Type: OSVDB ID: 6240 PHP-Nuke modules.php Recursive File Inclusion DoS Source: CCN Type: OSVDB ID: 6241 PHP-Nuke modules.php Local Arbitrary Code Execution Source: BID Type: Exploit, Vendor Advisory 3149 Source: CCN Type: BID-3149 PHP-Nuke Remote SQL Query Manipulation Vulnerability Source: XF Type: UNKNOWN php-nuke-prefix-admin-access(6945) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |