Multiple SQL injection vulnerabilities in PHP-Nuke 7.8 allow remote attackers to modify SQL queries and execute arbitrary PHP code via (1) the username parameter in the Your Account page, (2) the url parameter in the Downloads module, and (3) the description parameter in the Web_Links module.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2005-10-25T04:00:00
Updated: 2024-08-07T23:10:08.528Z
Reserved: 2005-10-26T00:00:00
Link: CVE-2005-3304
Vulnrichment
No data.
NVD
Status : Modified
Published: 2005-10-26T01:02:00.000
Modified: 2024-11-21T00:01:34.643
Link: CVE-2005-3304
Redhat
No data.