This Perl script exploits a SQL injection vulnerability in PHP-Nuke's Download module via the 'cid' parameter to extract user credentials (aid and password hash) from the 'nuke_authors' table. It sends a crafted HTTP GET request to retrieve the data.
Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:PHP-Nuke versions 6.0, 6.5, 6.9
No auth needed
Prerequisites:Target must be running PHP-Nuke with the Download module enabled · MySQL version > 4.0