Record summary

CVE-2007-1061 has a selected CVSS score of 6.8; EIP currently links 3 catalogued exploits.

Description

SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" block is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header (HTTP_REFERER variable).

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
3

Proofs of concept

3

Catalogued exploits

ExploitDBPHP-Nuke 8.0 Final - 'INSERT' Blind SQL Injection (MySQL)ExploitDB exploitby kraszaNot analyzed1 file
ExploitDB

PoC details
ExploitDBPHP-Nuke 8.0 Final - 'INSERT' SQL InjectionExploitDB exploitby kraszaNot analyzed1 file
ExploitDB

PoC details
ExploitDBPHP-Nuke 8.0 Final - HTTP Referers SQL InjectionExploitDB exploitby kraszaNot analyzed1 file
ExploitDB

PoC details

References

9