Lucene search

K
nvd[email protected]NVD:CVE-2006-5525
HistoryOct 26, 2006 - 4:07 p.m.

CVE-2006-5525

2006-10-2616:07:00
web.nvd.nist.gov
1

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.045

Percentile

92.5%

Incomplete blacklist vulnerability in mainfile.php in PHP-Nuke 7.9 and earlier allows remote attackers to conduct SQL injection attacks via (1) “//UNION " or (2) " UNION//” sequences, which are not rejected by the protection mechanism, as demonstrated by a SQL injection via the eid parameter in a search action in the Encyclopedia module in modules.php.

Affected configurations

Nvd
Node
phpnukephp-nukeRange7.9
OR
phpnukephp-nukeMatch7.0
OR
phpnukephp-nukeMatch7.1
OR
phpnukephp-nukeMatch7.2
OR
phpnukephp-nukeMatch7.3
OR
phpnukephp-nukeMatch7.4
OR
phpnukephp-nukeMatch7.5
OR
phpnukephp-nukeMatch7.6
OR
phpnukephp-nukeMatch7.7
OR
phpnukephp-nukeMatch7.8
VendorProductVersionCPE
phpnukephp-nuke*cpe:2.3:a:phpnuke:php-nuke:*:*:*:*:*:*:*:*
phpnukephp-nuke7.0cpe:2.3:a:phpnuke:php-nuke:7.0:*:*:*:*:*:*:*
phpnukephp-nuke7.1cpe:2.3:a:phpnuke:php-nuke:7.1:*:*:*:*:*:*:*
phpnukephp-nuke7.2cpe:2.3:a:phpnuke:php-nuke:7.2:*:*:*:*:*:*:*
phpnukephp-nuke7.3cpe:2.3:a:phpnuke:php-nuke:7.3:*:*:*:*:*:*:*
phpnukephp-nuke7.4cpe:2.3:a:phpnuke:php-nuke:7.4:*:*:*:*:*:*:*
phpnukephp-nuke7.5cpe:2.3:a:phpnuke:php-nuke:7.5:*:*:*:*:*:*:*
phpnukephp-nuke7.6cpe:2.3:a:phpnuke:php-nuke:7.6:*:*:*:*:*:*:*
phpnukephp-nuke7.7cpe:2.3:a:phpnuke:php-nuke:7.7:*:*:*:*:*:*:*
phpnukephp-nuke7.8cpe:2.3:a:phpnuke:php-nuke:7.8:*:*:*:*:*:*:*

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.045

Percentile

92.5%

Related for NVD:CVE-2006-5525