32863vdb entry
http://osvdb.org/32863 CVE-2007-0309
PHP-Nuke 7.x - 'Block-Old_Articles.php' SQL Injection
Record summary
CVE-2007-0309 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in blocks/block-Old_Articles.php in Francisco Burzi PHP-Nuke 7.9 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPHP-Nuke 7.x - 'Block-Old_Articles.php' SQL InjectionExploitDB exploitby PaisteristNot analyzed1 file
References
923748Third-party advisory
http://secunia.com/advisories/23748 2153Third-party advisory
http://securityreason.com/securityalert/2153 1017511vdb entry
http://securitytracker.com/id?1017511 neosecurityteam.net
http://www.neosecurityteam.net/advisories/PHP-Nuke--7.9-Old-Articles-Block-cat-SQL-Injection-vulnerability-31.html 20070113 PHP-Nuke <= 7.9 Old-Articles Block "cat" SQL Injection vulnerabilitymailing list
http://www.securityfocus.com/archive/1/456787/100/0/threaded 22037vdb entry
http://www.securityfocus.com/bid/22037 phpnuke-blockoldarticles-sql-injection(31482)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/31482 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-0309