TCH-Rob Posted January 18, 2006 Posted January 18, 2006 PHPNuke EV Search Module SQL Injection Vulnerability PHPNuke EV is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query. Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation. PHPNuke EV version 7.7 is vulnerable; earlier versions may also be affected. and PHPNuke Multiple Modules IMG Tag HTML Injection Vulnerability The PHPNuke Pool and News Modules are prone to an HTML injection vulnerability. This issue is due to a failure in the application modules to properly sanitize user-supplied input before using it in dynamically generated content. Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.