Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2004-0269SQL Injection in Burzi Php-nuke

5 documents4 sources
Severity
6.4MEDIUMNVD
EPSS
0.1%
top 71.95%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedNov 23
Latest updateApr 29

Description

SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module.

CVSS vector

AV:N/AC:L/C:P/I:P/A:NExploitability: 10.0 | Impact: 4.9

Affected Packages1 packages

NVDfrancisco_burzi/php-nuke26 versions+25

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xfcm-6xgr-cx4p: SQL injection vulnerability in PHP-Nuke 62022-04-29
CVEList
CVE-2004-0269: SQL injection vulnerability in PHP-Nuke 62004-03-18

💥Exploits & PoCs

2
Exploit-DB
PHP-Nuke 6.x - 'Category' SQL Injection2003-12-23
Exploit-DB
PHP-Nuke 5.x/6.x Web_Links Module - SQL Injection2003-05-12
CVE-2004-0269 — SQL Injection in Burzi Php-nuke | cvebase