CVE-2014-3934: SQL Injection
Published Jun 2, 2014
·Updated
SQL injection vulnerability in the SubmitNews module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL commands via the topics[] parameter to modules.php.
Affected Software
2 affected components
Phpnuke Php-nuke=8.3
Phpnuke Submit News Module
Event History
Jun 2, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3934?
The severity of CVE-2014-3934 is considered high due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2014-3934?
To fix CVE-2014-3934, upgrade PHP-Nuke to a version beyond 8.3 that no longer contains the vulnerability.
3
What does CVE-2014-3934 affect?
CVE-2014-3934 affects the Submit_News module in PHP-Nuke version 8.3.
4
How can attackers exploit CVE-2014-3934?
Attackers can exploit CVE-2014-3934 by sending specially crafted requests with malicious SQL commands via the topics[] parameter.
5
Is CVE-2014-3934 a known vulnerability in PHP-Nuke?
Yes, CVE-2014-3934 is a known SQL injection vulnerability in PHP-Nuke that has been documented in security databases.