Vulnerability Name: | CVE-2008-0461 (CCN-39850) | ||||||||
Assigned: | 2008-01-22 | ||||||||
Published: | 2008-01-22 | ||||||||
Updated: | 2017-09-29 | ||||||||
Summary: | SQL injection vulnerability in index.php in the Search module in PHP-Nuke 8.0 FINAL and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the sid parameter in a comments action to modules.php. Note: some of these details are obtained from third party information. | ||||||||
CVSS v3 Severity: | 4.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 6.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:U/RC:UR)
5.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:H/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-89 | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-0461 Source: CCN Type: SA28624 PHP-Nuke "modules/Search/index.php" SQL Injection Source: SECUNIA Type: Vendor Advisory 28624 Source: CCN Type: OSVDB ID: 40831 PHP-Nuke modules/Search/index.php sid Parameter SQL Injection Source: CCN Type: PHP-Nuke Web site PHP-Nuke Source: BID Type: Exploit 27408 Source: CCN Type: BID-27408 PHP-Nuke Search Module 'sid' Parameter SQL Injection Vulnerability Source: VUPEN Type: UNKNOWN ADV-2008-0264 Source: XF Type: UNKNOWN phpnuke-index-search-sql-injection(39850) Source: XF Type: UNKNOWN phpnuke-index-search-sql-injection(39850) Source: EXPLOIT-DB Type: UNKNOWN 4965 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |