Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHP-Nuke Lang Parameter Local File Include and SQL Injection Vulnerabilities

PHP-Nuke is prone to local file-include and SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input.

Exploiting this issue could allow an attacker to retrieve arbitary files, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

These issues affect version 8.0; other versions may also be vulnerable.







 

Privacy Statement
Copyright 2009, SecurityFocus