Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-0906. PoCs published by DamaR.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in PHP-Nuke's Docum module, allowing unauthorized extraction of admin credentials from the nuke_authors table. The attack leverages a malformed artid parameter to inject a UNION-based SQL query.
Description
SQL injection vulnerability in the Docum module in PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parameter in a viewarticle operation.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in PHP-Nuke's Docum module, allowing unauthorized extraction of admin credentials from the nuke_authors table. The attack leverages a malformed artid parameter to inject a UNION-based SQL query.