CVE-2006-5525

Phpnuke Php-nuke < 7.9 - SQL Injection

Title source: rule

Description

Incomplete blacklist vulnerability in mainfile.php in PHP-Nuke 7.9 and earlier allows remote attackers to conduct SQL injection attacks via (1) "/**/UNION " or (2) " UNION/**/" sequences, which are not rejected by the protection mechanism, as demonstrated by a SQL injection via the eid parameter in a search action in the Encyclopedia module in modules.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Paisterist · phpwebappsphp
https://www.exploit-db.com/exploits/2617

Scores

EPSS 0.0253
EPSS Percentile 85.5%

Details

Status published
Products (10)
phpnuke/php-nuke 7.0
phpnuke/php-nuke 7.1
phpnuke/php-nuke 7.2
phpnuke/php-nuke 7.3
phpnuke/php-nuke 7.4
phpnuke/php-nuke 7.5
phpnuke/php-nuke 7.6
phpnuke/php-nuke 7.7
phpnuke/php-nuke 7.8
phpnuke/php-nuke < 7.9
Published Oct 26, 2006
Tracked Since Feb 18, 2026