First published: Fri Jul 23 2004(Updated: )
SQL injection vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to execute arbitrary SQL statements via the instory parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP-Nuke | =8.0_final |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0732 is considered a high severity vulnerability due to its potential for remote SQL execution.
To fix CVE-2004-0732, ensure you upgrade to a patched version of PHP-Nuke that addresses this SQL injection issue.
CVE-2004-0732 affects Php-Nuke version 8.0_final and possibly earlier versions of the software.
Exploitation of CVE-2004-0732 could allow attackers to manipulate your database or gain unauthorized access to sensitive information.
You can identify vulnerability to CVE-2004-0732 by reviewing your PHP-Nuke version and inspecting the Search module for the `instory` parameter handling.