CVE-2004-0266: SQL Injection
SQL injection vulnerability in the "public message" capability (publicmessage) for Php-Nuke 6.x to 7.1.0 allows remote attackers to obtain the administrator password via the cmid parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0266?
CVE-2004-0266 is considered a high severity vulnerability due to the potential for remote attackers to exploit it and gain access to sensitive information.
How do I fix CVE-2004-0266?
To fix CVE-2004-0266, it is recommended to update to a patched version of PHP-Nuke that addresses this SQL injection vulnerability.
What versions of PHP-Nuke are affected by CVE-2004-0266?
CVE-2004-0266 affects PHP-Nuke versions from 6.0 to 7.1, including various release candidates and betas.
Can CVE-2004-0266 be exploited remotely?
Yes, CVE-2004-0266 can be exploited remotely by attackers through manipulated requests.
What impact does CVE-2004-0266 have on PHP-Nuke users?
The impact of CVE-2004-0266 on PHP-Nuke users includes the risk of unauthorized access to administrator credentials and control over the website.