| |||||||||||||
| CVE ID: | CVE-2003-0279 |
| Description: | Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php. |
| Test IDs: | 1.3.6.1.4.1.25623.1.0.52438 |
| Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2003-0279 Bugtraq: 20030512 Lot of SQL injection on PHP-Nuke 6.5 (secure weblog!) (Google Search) http://marc.theaimsgroup.com/?l=bugtraq&m=105276019312980&w=2 Bugtraq: 20030513 More and More SQL injection on PHP-Nuke 6.5. (Google Search) http://archives.neohapsis.com/archives/bugtraq/2003-05/0147.html BugTraq ID: 7558 http://www.securityfocus.com/bid/7558 BugTraq ID: 7588 http://www.securityfocus.com/bid/7588 XForce ISS Database: phpnuke-web-sql-injection(11984) http://xforce.iss.net/xforce/xfdb/11984 |
|