CVE-2002-1242: SQL Injection
Published Nov 12, 2002
·Updated
SQL injection vulnerability in PHP-Nuke before 6.0 allows remote authenticated users to modify the database and gain privileges via the "bio" argument to modules.php.
Affected Software
1 affected component
Francisco Burzi PHP-Nuke=5.6
Remediation
Patch Available
Event History
Nov 12, 2002
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1242?
CVE-2002-1242 is classified as a high severity vulnerability due to its potential for unauthorized database modifications.
2
How do I fix CVE-2002-1242?
To fix CVE-2002-1242, upgrade PHP-Nuke to version 6.0 or later to eliminate the SQL injection vulnerability.
3
Who is affected by CVE-2002-1242?
Users of PHP-Nuke versions prior to 6.0 are affected by CVE-2002-1242.
4
What type of vulnerability is CVE-2002-1242?
CVE-2002-1242 is an SQL injection vulnerability that allows remote authenticated users to manipulate the database.
5
Can CVE-2002-1242 lead to privilege escalation?
Yes, CVE-2002-1242 can potentially allow remote authenticated users to gain higher privileges on the affected system.