漏洞信息详情

PHPNuke Search模块SQL注入漏洞

漏洞简介

phpnuke是一套开放源码建站程序。

PHP-Nuke 7.8以及patch 3.1的7.9之前的其他版本中search模块内存在多个SQL注入漏洞,可让远程攻击者执行任意SQL命令.

漏洞公告

参考网址

来源: XF

名称: phpnuke-query-sql-injection(23079)

链接:http://xforce.iss.net/xforce/xfdb/23079

来源: BID

名称: 15421

链接:http://www.securityfocus.com/bid/15421

来源: MISC

链接:http://securityreason.com/achievement_exploitalert/5

来源: SECUNIA

名称: 17543

链接:http://secunia.com/advisories/17543/

来源: BUGTRAQ

名称: 20051115 Critical SQL Injection PHPNuke <= 7.8

链接:http://marc.theaimsgroup.com/?l=bugtraq&m=113210758511323&w=2

来源: MISC

链接:http://www.waraxe.us/advisory-46.html

来源: BUGTRAQ

名称: 20060219 [waraxe-2006-SA#046] - Critical sql injection in phpNuke 7.5-7.8

链接:http://www.securityfocus.com/archive/1/archive/1/425508/100/0/threaded

来源: BUGTRAQ

名称: 20060221 Re: [waraxe-2006-SA#046] - Critical sql injection in phpNuke 7.5-7.8

链接:http://www.securityfocus.com/archive/1/425627/100/0/threaded

来源: OSVDB

名称: 20866

链接:http://www.osvdb.org/20866

来源: VUPEN

名称: ADV-2005-2446

链接:http://www.frsirt.com/english/advisories/2005/2446

来源: SECTRACK

名称: 1015651

链接:http://securitytracker.com/id?1015651

来源: SECTRACK

名称: 1015215

链接:http://securitytracker.com/id?1015215

来源: FULLDISC

名称: 20051115 Critical SQL Injection PHPNuke <= 7.8

链接:http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0454.html

补丁

    暂无

漏洞信息快速查询

相关漏洞

更多