Multiple SQL injection vulnerabilities in the Search module in PHP-Nuke 7.8, and possibly other versions before 7.9 with patch 3.1, allows remote attackers to execute arbitrary SQL commands, as demonstrated via the query parameter in a stories type.
2005-11-24T11:03:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? | 
|---|---|---|---|---|
| Application | francisco_burzi | php-nuke | 7.0_final | Yes | 
| Application | francisco_burzi | php-nuke | 7.1 | Yes | 
| Application | francisco_burzi | php-nuke | 7.2 | Yes | 
| Application | francisco_burzi | php-nuke | 7.3 | Yes | 
| Application | francisco_burzi | php-nuke | 7.6 | Yes | 
| Application | francisco_burzi | php-nuke | 7.7 | Yes | 
| Application | francisco_burzi | php-nuke | 7.8 | Yes |