vendor:
PHPNuke
by:
Fabrizi Andrea
7.5
CVSS
HIGH
Remote SQL Injection
89
CWE
Product Name: PHPNuke
Affected Version From: All versions of PHPNuke prior to the latest version
Affected Version To: Latest version of PHPNuke
Patch Exists: NO
Related CWE:
CPE: a:phpnuke:phpnuke
Platforms Tested:
2005
PHPNuke Top Module Remote SQL Injection
This is a script that exploits a remote SQL injection vulnerability in the PHPNuke Top Module. It allows an attacker to retrieve the passwords hashes of the admin users.
Mitigation:
The vulnerability has been patched in the latest version of PHPNuke. It is recommended to update to the latest version to mitigate the risk.