CVE-2005-0996: SQL Injection
Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the email or url parameters in the Add function, (2) the min parameter in the viewsdownload function, or (3) the min parameter in the search function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0996?
CVE-2005-0996 is rated as a medium severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2005-0996?
To fix CVE-2005-0996, you should update the PHP-Nuke software to a version that has patched these SQL injection vulnerabilities.
What are the potential impacts of CVE-2005-0996?
The potential impacts of CVE-2005-0996 include unauthorized access to database information and execution of arbitrary web scripts.
Which versions of PHP-Nuke are affected by CVE-2005-0996?
CVE-2005-0996 affects PHP-Nuke version 7.6.
What are the exploit vectors for CVE-2005-0996?
Exploit vectors for CVE-2005-0996 include manipulating the email, url, and min parameters in specific functions of the Downloads module.