First published: Wed Apr 19 2006(Updated: )
SQL injection vulnerability in the Your_Account module in PHP-Nuke 7.8 might allows remote attackers to execute arbitrary SQL commands via the user_id parameter in the Your_Home functionality. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP-Nuke | =7.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1847 is classified with a medium severity rating due to its potential for remote SQL injection attacks.
To fix CVE-2006-1847, upgrade PHP-Nuke to a version later than 7.8 or apply patches that specifically address the SQL injection issue.
CVE-2006-1847 allows remote attackers to execute arbitrary SQL commands, which can lead to unauthorized data access or modification.
CVE-2006-1847 specifically affects PHP-Nuke version 7.8.
Yes, CVE-2006-1847 is considered easily exploitable as it involves a common SQL injection vulnerability.