5.1

CVE-2006-5525

Exploit

Incomplete blacklist vulnerability in mainfile.php in PHP-Nuke 7.9 and earlier allows remote attackers to conduct SQL injection attacks via (1) "/**/UNION " or (2) " UNION/**/" sequences, which are not rejected by the protection mechanism, as demonstrated by a SQL injection via the eid parameter in a search action in the Encyclopedia module in modules.php.

Data is provided by the National Vulnerability Database (NVD)
PhpnukePhp-nuke Version <= 7.9
PhpnukePhp-nuke Version7.0
PhpnukePhp-nuke Version7.1
PhpnukePhp-nuke Version7.2
PhpnukePhp-nuke Version7.3
PhpnukePhp-nuke Version7.4
PhpnukePhp-nuke Version7.5
PhpnukePhp-nuke Version7.6
PhpnukePhp-nuke Version7.7
PhpnukePhp-nuke Version7.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.51% 0.805
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P