CVE-2010-5083

PHP-Nuke Web_Links Module - SQL Injection via URL Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-5083. PoCs published by ITSecTeam.

AI-analyzed exploit summary The code describes a blind SQL injection vulnerability in PHP-Nuke 8.x.x, specifically in the Web_Links module. It identifies the vulnerable parameter 'url' in the Add function and provides a proof-of-concept URL for exploitation.

Description

SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter in an Add action to modules.php.

Exploits (1)

exploitdb WRITEUP
by ITSecTeam · textwebappsphp
https://www.exploit-db.com/exploits/14589

The code describes a blind SQL injection vulnerability in PHP-Nuke 8.x.x, specifically in the Web_Links module. It identifies the vulnerable parameter 'url' in the Add function and provides a proof-of-concept URL for exploitation.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: PHP-Nuke 8.x.x
No auth needed
Prerequisites: Access to the vulnerable PHP-Nuke installation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/14589
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/61012

Scores

EPSS 0.0111
EPSS Percentile 61.7%

Details

CWE
CWE-89
Status published
Products (2)
phpnuke/php-nuke 8.0
phpnuke/web_links_module
Published Feb 14, 2012
Tracked Since Feb 18, 2026