Vulnerability Name: | CVE-2004-0266 (CCN-15080) | ||||||||
Assigned: | 2004-02-09 | ||||||||
Published: | 2004-02-09 | ||||||||
Updated: | 2017-07-19 | ||||||||
Summary: | SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote attackers to obtain the administrator password via the c_mid parameter. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Sun Feb 08 2004 - 14:15:31 CST SQL injection in Php-Nuke 7.1.0 Source: MITRE Type: CNA CVE-2004-0266 Source: BUGTRAQ Type: UNKNOWN 20040208 [waraxe-2004-SA#003] - SQL injection in Php-Nuke 7.1.0 Source: CCN Type: PHP-Nuke Web site PHP-Nuke Source: CCN Type: OSVDB ID: 3901 PHP-Nuke mainfile.php c_mid Parameter SQL Injection Source: BID Type: Exploit, Vendor Advisory 9615 Source: CCN Type: BID-9615 PHP-Nuke Public Message SQL Injection Vulnerability Source: XF Type: UNKNOWN phpnuke-publicmessage-sql-injection(15080) Source: XF Type: UNKNOWN phpnuke-publicmessage-sql-injection(15080) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |