Release date:
Updated on:
Affected Systems:
PHP-Nuke PHP-nuke8.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56700
PHP-Nuke is a website creation and management tool. It can use many database software as the backend, such as MySQL, PostgreSQL, mSQL, Interbase, and Sybase.
PHP-Nuke 8.2 and other versions of modules. the php page does not check the validity of the 'sid' parameter, resulting in an SQL injection vulnerability. Attackers can exploit this vulnerability to damage applications, access or modify data, and exploit potential vulnerabilities in backend databases.
<* Source: Ashiyane Digital Security Team
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/modules.php? Name = News & amp; file = article & amp; sid = 13 [SQL]
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
PHP-Nuke
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://phpnuke.org/