CVE-2003-1210
Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to the getit function or the (2) min parameter to the search function.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.37%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to the getit function or the (2) min parameter to the search function.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 5.37% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- francisco burzi/php-nuke
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2003-05/0147.htmlExploit
- http://www.securityfocus.com/bid/7588Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11984
- http://archives.neohapsis.com/archives/bugtraq/2003-05/0147.htmlExploit
- http://www.securityfocus.com/bid/7588Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11984
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.