PHPNuke Multiple Modules SQL Injection Vulnerabilities

No exploit is required.

The following proof of concept URI are available:
http://www.example.com/modules.php?name=Downloads&d_op=Add&url=[SQL]&title=what&description=what
http://www.example.com/modules.php?name=Web_Links&l_op=Add&title=what&description=[SQL]&url=what

The following proof of concept exploit is also available:


 

Privacy Statement
Copyright 2010, SecurityFocus