CVE-2005-3304

PHP-Nuke 7.8 - SQL Injection via Username Parameter, Downloads URL Parameter, and Web_Links Description Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-3304.

AI-analyzed exploit summary The exploit demonstrates a blind SQL injection vulnerability in the Downloads module for PHP-Nuke. It uses ASCII-based substring extraction to leak admin and user credentials from the database by manipulating the 'url' parameter in the 'Add' operation.

Description

Multiple SQL injection vulnerabilities in PHP-Nuke 7.8 allow remote attackers to modify SQL queries and execute arbitrary PHP code via (1) the username parameter in the Your Account page, (2) the url parameter in the Downloads module, and (3) the description parameter in the Web_Links module.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/32747

The exploit demonstrates a blind SQL injection vulnerability in the Downloads module for PHP-Nuke. It uses ASCII-based substring extraction to leak admin and user credentials from the database by manipulating the 'url' parameter in the 'Add' operation.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: PHP-Nuke Downloads module
No auth needed
Prerequisites: Access to the vulnerable PHP-Nuke instance · Downloads module enabled
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (9)

Core 9
Core References
Exploit, Vendor Advisory x_refsource_misc
http://rgod.altervista.org/phpnuke78sql.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/22851
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15178
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=113017049702436&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/20293
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17315/
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/20292
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/2191
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/20291

Scores

EPSS 0.0563
EPSS Percentile 91.9%

Details

Status published
Products (1)
francisco_burzi/php-nuke 7.8
Published Oct 26, 2005
Tracked Since Feb 18, 2026