CVE-2007-1061: SQL Injection
Published Feb 22, 2007
·Updated
SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" block is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header (HTTPREFERER variable).
Affected Software
1 affected component
Francisco Burzi PHP-Nuke<=8.0_final
Event History
Feb 22, 2007
CVE Published
12:28 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1061?
CVE-2007-1061 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2007-1061?
To fix CVE-2007-1061, disable the HTTP Referers block or update to a newer version of PHP-Nuke that addresses this vulnerability.
3
Who is affected by CVE-2007-1061?
CVE-2007-1061 affects all versions of PHP-Nuke up to and including 8.0 Final.
4
What kind of attack is possible with CVE-2007-1061?
CVE-2007-1061 allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header.
5
Is there any workaround for CVE-2007-1061?
A possible workaround for CVE-2007-1061 is to disable the HTTP Referers block in the PHP-Nuke configuration.