CVE-2009-0302: SQL Injection
Published Jan 27, 2009
·Updated
SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arbitrary SQL commands via the url parameter in the Add operation to modules.php.
Affected Software
1 affected component
PHP-Nuke Downloads module=8.0
Event History
Jan 27, 2009
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0302?
CVE-2009-0302 has a high severity rating due to its potential for remote SQL command execution.
2
How do I fix CVE-2009-0302?
To fix CVE-2009-0302, upgrade to a version of PHP-Nuke that is patched against this SQL injection vulnerability.
3
Who is affected by CVE-2009-0302?
CVE-2009-0302 affects remote authenticated users of PHP-Nuke versions 8.0, 8.1, 0.3, 5b and earlier.
4
What type of vulnerability is CVE-2009-0302?
CVE-2009-0302 is an SQL injection vulnerability in the Downloads module of PHP-Nuke.
5
Can CVE-2009-0302 be exploited remotely?
Yes, CVE-2009-0302 can be exploited remotely by authenticated users to execute arbitrary SQL commands.