Exploit PHP-Nuke 5.x/6.x Web_Links Module - SQL Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
22589
Проверка EDB
  1. Пройдено
Автор
ALBERT PUIGSECH GALICIA
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2004-0269
Дата публикации
2003-05-12
Код:
source: https://www.securityfocus.com/bid/7558/info

It has been reported that multiple input validation bugs exist in the Web_Links module used by PHPNuke. Because of this, a remote user may be able to access the database and potentially gain access to sensitive information. Successful exploitation could result in compromise of the web forums or more severe consequences. 

http://www.example.com/modules.php?op=modload&name=Web_Links&file=index&l_op=viewlink&cid=2%20<our_code>

where <our_code> represents attacker-supplied SQL code.
 
Источник
www.exploit-db.com

Похожие темы