CVE-2003-1435: SQL Injection
Published Dec 31, 2003
·Updated
SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module.
Affected Software
2 affected components
Francisco Burzi PHP-Nuke=5.6
Francisco Burzi PHP-Nuke=6.0
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Oct 23, 2007
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1435?
CVE-2003-1435 is classified as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2003-1435?
To fix CVE-2003-1435, upgrading to a secure version of PHP-Nuke beyond 6.0 is recommended.
3
What applications are affected by CVE-2003-1435?
CVE-2003-1435 affects PHP-Nuke versions 5.6 and 6.0.
4
What type of attack is CVE-2003-1435 associated with?
CVE-2003-1435 is associated with SQL injection attacks that allow remote execution of arbitrary SQL commands.
5
Is CVE-2003-1435 easy to exploit?
CVE-2003-1435 can be easily exploited by attackers familiar with SQL injection techniques.