CVE-2004-1932

Francisco Burzi Php-nuke - SQL Injection

Title source: rule
STIX 2.1

Description

SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by iko94 · perlwebappsphp
https://www.exploit-db.com/exploits/465

Scores

EPSS 0.0002
EPSS Percentile 5.9%

Details

Status published
Products (14)
francisco_burzi/php-nuke 6.0
francisco_burzi/php-nuke 6.5
francisco_burzi/php-nuke 6.5_beta1
francisco_burzi/php-nuke 6.5_final
francisco_burzi/php-nuke 6.5_rc1
francisco_burzi/php-nuke 6.5_rc2
francisco_burzi/php-nuke 6.5_rc3
francisco_burzi/php-nuke 6.6
francisco_burzi/php-nuke 6.7
francisco_burzi/php-nuke 6.9
... and 4 more
Published Apr 12, 2004
Tracked Since Feb 18, 2026