header-logo
Suggest Exploit
vendor:
PostNuke Phoenix
by:
SecurityFocus
7.5
CVSS
HIGH
Remote SQL Injection
89
CWE
Product Name: PostNuke Phoenix
Affected Version From: PostNuke Phoenix
Affected Version To: PostNuke Phoenix
Patch Exists: YES
Related CWE: N/A
CPE: a:postnuke:postnuke_phoenix
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2004

A remote SQL Injection vulnerability affects PostNuke Phoenix

PostNuke Phoenix is vulnerable to a remote SQL injection vulnerability due to a failure of the application to properly sanitize user-supplied input prior to including it in SQL queries. An attacker can exploit this vulnerability to manipulate SQL queries to the underlying database, potentially leading to the theft of sensitive information, including authentication credentials, and data corruption.

Mitigation:

Input validation should be used to ensure that user-supplied data is properly sanitized prior to being included in SQL queries.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/13077/info

A remote SQL Injection vulnerability affects PostNuke Phoenix. This issue is due to a failure of the application to properly sanitize user-supplied input prior to including it in SQL queries.

An attacker may exploit this issue to manipulate SQL queries to the underlying database. This may facilitate theft sensitive information, potentially including authentication credentials, and data corruption.

http://localhost/modules.php?op=modload&name=News&file=article&sid='SQL_INJECTION&POSTNUKESID=355776cfb622466924a7096d4471a480