Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHP-Nuke Image Tag Admin Command Execution Vulnerability

It has been reported that PHP-Nuke is prone to a remote admin command execution vulnerability. This issue is due to a design error that allows an attacker to specify arbitrary URI values in bbCode tags contained within posts.

This issue may be leveraged to force an admin user viewing a malicious post to perform some query to the affected application such as adding a user or removing arbitrary data from the database.







 

Privacy Statement
Copyright 2009, SecurityFocus