Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2002-1242SQL Injection in Burzi Php-nuke

4 documents4 sources
Severity
7.5HIGHNVD
EPSS
0.1%
top 74.84%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedNov 12
Latest updateApr 30

Description

SQL injection vulnerability in PHP-Nuke before 6.0 allows remote authenticated users to modify the database and gain privileges via the "bio" argument to modules.php.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vwr7-54pf-g58r: SQL injection vulnerability in PHP-Nuke before 62022-04-30
CVEList
CVE-2002-1242: SQL injection vulnerability in PHP-Nuke before 62004-09-01

💥Exploits & PoCs

1
Exploit-DB
PHP-Nuke 5.6 - 'modules.php' SQL Injection2002-11-01