CVE-2001-1025: Critical severity Francisco Burzi PHP-Nuke vulnerability
Published Aug 31, 2001
·Updated
PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php.
Affected Software
2 affected components
Francisco Burzi PHP-Nuke=5.0
Francisco Burzi PHP-Nuke=5.0.1
Event History
Aug 31, 2001
CVE Published
04:00 AM
Feb 2, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1025?
CVE-2001-1025 is considered a critical vulnerability due to the potential for arbitrary SQL execution.
2
How do I fix CVE-2001-1025?
To fix CVE-2001-1025, upgrade to PHP-Nuke version 5.0.2 or later where the vulnerability has been patched.
3
What systems are affected by CVE-2001-1025?
CVE-2001-1025 affects PHP-Nuke versions 5.0 and 5.0.1.
4
What type of attack does CVE-2001-1025 enable?
CVE-2001-1025 enables remote attackers to perform arbitrary SQL operations.
5
Can CVE-2001-1025 be exploited without authentication?
Yes, CVE-2001-1025 can be exploited by remote attackers without needing authentication.