Vulnerability Name: | CVE-2005-3304 (CCN-22851) | ||||||||
Assigned: | 2005-10-25 | ||||||||
Published: | 2005-10-25 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Multiple SQL injection vulnerabilities in PHP-Nuke 7.8 allow remote attackers to modify SQL queries and execute arbitrary PHP code via (1) the username parameter in the Your Account page, (2) the url parameter in the Downloads module, and (3) the description parameter in the Web_Links module. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Sun Oct 23 2005 - 18:33:54 CDT PhpNuke 7.8 with all security fixes/patches "Your_Account", "Downloads", "Web Links" SQL Injection / Remote commans execution Source: MITRE Type: CNA CVE-2005-3304 Source: BUGTRAQ Type: UNKNOWN 20051023 PhpNuke 7.8 with all security fixes/patches "Your_Account", Source: MISC Type: Exploit, Vendor Advisory http://rgod.altervista.org/phpnuke78sql.html Source: CCN Type: SA17315 PHP-Nuke SQL Injection Vulnerabilities Source: SECUNIA Type: Vendor Advisory 17315 Source: OSVDB Type: UNKNOWN 20291 Source: OSVDB Type: UNKNOWN 20292 Source: OSVDB Type: UNKNOWN 20293 Source: CCN Type: OSVDB ID: 20291 PHP-Nuke Your Account Username Field SQL Injection Source: CCN Type: OSVDB ID: 20292 Downloads Module for PHP-Nuke modules.php url Parameter SQL Injection Source: CCN Type: OSVDB ID: 20293 PHP-Nuke Web_Links Module description Parameter SQL Injection Source: CCN Type: PHP-Nuke Web site PHP-Nuke Source: BID Type: UNKNOWN 15178 Source: CCN Type: BID-15178 PHPNuke Multiple Modules SQL Injection Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2005-2191 Source: XF Type: UNKNOWN phpnuke-multiple-modules-sql-injection(22851) Source: XF Type: UNKNOWN phpnuke-multiple-modules-sql-injection(22851) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |