CVE-2004-0738: SQL Injection
Published Jul 23, 2004
·Updated
Multiple SQL injection vulnerabilities in the Search module in Php-Nuke allow remote attackers to execute arbitrary SQL via the (1) min or (2) categ parameters.
Affected Software
1 affected component
Francisco Burzi PHP-Nuke=8.0_final
Event History
Jul 23, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0738?
CVE-2004-0738 is classified as a high severity vulnerability due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2004-0738?
To fix CVE-2004-0738, you should upgrade to a patched version of PHP-Nuke that addresses SQL injection vulnerabilities.
3
What are the affected versions of PHP-Nuke in CVE-2004-0738?
CVE-2004-0738 specifically affects PHP-Nuke version 8.0_final.
4
What types of parameters are exploited in CVE-2004-0738?
The parameters exploited in CVE-2004-0738 are 'min' and 'categ' within the Search module.
5
Can CVE-2004-0738 lead to data breaches?
Yes, CVE-2004-0738 can lead to data breaches as attackers can execute arbitrary SQL commands to manipulate the database.