CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:H/Au:N/C:P/I:N/A:N
AI Score
Confidence
Low
EPSS
Percentile
73.0%
Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php.
Vendor | Product | Version | CPE |
---|---|---|---|
francisco_burzi | php-nuke | 5.0 | cpe:2.3:a:francisco_burzi:php-nuke:5.0:*:*:*:*:*:*:* |
francisco_burzi | php-nuke | 6.0 | cpe:2.3:a:francisco_burzi:php-nuke:6.0:*:*:*:*:*:*:* |