CVE-2007-1450: SQL Injection
Published Mar 14, 2007
·Updated
SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Top or News module via the lang parameter.
Affected Software
11 affected components
Phpnuke Php-nuke=7.3
Phpnuke Php-nuke=7.4
Phpnuke Php-nuke=7.1
Phpnuke Php-nuke=7.9
Phpnuke Php-nuke=8.0.0-final
Phpnuke Php-nuke=7.5
Phpnuke Php-nuke=7.2
Phpnuke Php-nuke=7.7
Phpnuke Php-nuke=7.8
Phpnuke Php-nuke=7.0
Phpnuke Php-nuke=7.6
Event History
Mar 14, 2007
CVE Published
06:19 PM
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1450?
CVE-2007-1450 is a critical vulnerability that allows remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2007-1450?
To fix CVE-2007-1450, update PHP-Nuke to version 8.0.1 or later where the vulnerability has been patched.
3
What versions of PHP-Nuke are affected by CVE-2007-1450?
CVE-2007-1450 affects PHP-Nuke versions 7.0 through 8.0.0-final.
4
What type of attack does CVE-2007-1450 enable?
CVE-2007-1450 enables SQL injection attacks, allowing unauthorized SQL commands to be executed.
5
Is there a known exploit for CVE-2007-1450?
Yes, there are known exploit techniques that take advantage of the SQL injection vulnerability in CVE-2007-1450.