First published: Tue Jul 14 2009(Updated: )
SQL injection vulnerability in modules.php in the Current_Issue module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a summary action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php-nuke Current Issue Module |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6866 is classified as a high severity vulnerability due to its potential for remote exploitation and arbitrary SQL command execution.
To fix CVE-2008-6866, upgrade to the latest version of the Current_Issue module for PHP-Nuke that addresses this SQL injection vulnerability.
Any users of the Current_Issue module for PHP-Nuke that do not have the security patch applied are susceptible to CVE-2008-6866.
CVE-2008-6866 is an SQL injection vulnerability that allows attackers to manipulate database queries.
Attackers can execute arbitrary SQL commands on the database of affected PHP-Nuke installations, potentially leading to data breaches.