Vulnerability Name: | CVE-2005-0997 (CCN-20009) | ||||||||
Assigned: | 2005-04-06 | ||||||||
Published: | 2005-04-06 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 7.6 allow remote attackers to execute arbitrary SQL commands via (1) the email or url parameters in the Add function, (2) the url parameter in the modifylinkrequestS function, (3) the orderby or min parameters in the viewlink function, (4) the orderby, min, or show parameters in the search function, or (5) the ratenum parameter in the MostPopular function. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 7.1 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:U/RC:UR)
7.1 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Apr 07 2005 - 11:05:59 CDT phpnuke 7.6 Multiple vulnerabilities in Web_Links Module cXIb8O3.14 Source: MITRE Type: CNA CVE-2005-0996 Source: MITRE Type: CNA CVE-2005-0997 Source: BUGTRAQ Type: UNKNOWN 20050403 [SECURITYREASON.COM] phpnuke 7.6 Multiple vulnerabilities in Web_Links Module cXIb8O3.14 Source: CCN Type: OSVDB ID: 15407 PHP-Nuke Downloads Module Multiple Parameter SQL Injection Source: CCN Type: OSVDB ID: 15408 PHP-Nuke Web_Links Multiple Parameter SQL Injection Source: CCN Type: PHP-Nuke Web site PHP-Nuke Source: CCN Type: BID-13055 PHP-Nuke Web_Links Module Multiple SQL Injection Vulnerabilities Source: CCN Type: BID-13061 PHP-Nuke Downloads Module Multiple SQL Injection Vulnerabilities Source: XF Type: UNKNOWN phpnuke-modulesphp-sql-injection(20009) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |