Description
Multiple SQL injection vulnerabilities in the Search module in PHP-Nuke 7.8, and possibly other versions before 7.9 with patch 3.1, allows remote attackers to execute arbitrary SQL commands, as demonstrated via the query parameter in a stories type.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by anonymous · perlwebappsphp
https://www.exploit-db.com/exploits/1326
References (13)
Scores
EPSS
0.6934
EPSS Percentile
98.7%
Details
Status
published
Products (7)
francisco_burzi/php-nuke
7.0_final
francisco_burzi/php-nuke
7.1
francisco_burzi/php-nuke
7.2
francisco_burzi/php-nuke
7.3
francisco_burzi/php-nuke
7.6
francisco_burzi/php-nuke
7.7
francisco_burzi/php-nuke
7.8
Published
Nov 24, 2005
Tracked Since
Feb 18, 2026