First published: Mon Sep 14 2009(Updated: )
SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the recipeid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP-Nuke Recipe module | =1.3 | |
PHP-Nuke Recipe module | =1.4 | |
PhpNuke |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-7226 is considered a critical vulnerability due to the potential for remote SQL injection and unauthorized database access.
To fix CVE-2008-7226, upgrade the PHP-Nuke Recipes module to the latest version that addresses this SQL injection vulnerability.
CVE-2008-7226 affects PHP-Nuke Recipe module versions 1.3 and 1.4.
Yes, CVE-2008-7226 can be exploited by unauthenticated remote attackers, making it particularly dangerous.
Exploiting CVE-2008-7226 can allow attackers to execute arbitrary SQL commands, potentially compromising the entire database.