SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-0269

SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links…

MEDIUM 6.4EPSS 8.09%

Does this matter?

Lower severity and a low EPSS score (8.09%). Track it; it rarely justifies an emergency change on its own.

Description

SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module.

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS
8.09% probability · 94th percentile
CISA KEV
Not listed
Affected
francisco burzi/php-nuke
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.