PHP Web Host - Quality Web Hosting For All PHP Applications $35/month $250/year (Unlimited) - $25/month - 200,000 impressions - Your Ad Could be Here - Click For Details
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
TheosEleos
Life Cycles Becoming CPU Cycles


Joined: Sep 18, 2003
Posts: 960
Location: Missouri

PostPosted: Fri Jan 09, 2004 12:17 pm Reply with quote Back to top

Is this true and is there a fix?

Quote:
(4) MODERATE: PHP-Nuke Multiple Modules SQL Injection
Affected: PHP-Nuke version 7.0 FINAL and possibly prior versions

Description:
The PHP-Nuke "Surveys" module contains an SQL injection vulnerability
in handling data supplied to the "pollID" parameter. Remote attackers
can exploit the flaw to manipulate SQL queries issued against the
backend database, potentially leading to compromise of the PHP-Nuke
application. Further, the vendor's announcement of a fix indicates that
additional SQL injection vulnerabilities have been found in the "Forums"
and "Reviews" modules. Technical details have been posted.

Status: The vendor has corrected the problems in the latest release of
PHP-Nuke version 7.0 FINAL. The new version is available to PHP-Nuke
Club Members only.

Council Site Actions: The affected software is not in production or
widespread use at any of the council sites. Most sites reported that no
action was necessary. A few sites did send out a notice to their
respective support groups as an FYI.
View user's profile Send private message Visit poster's website AIM Address ICQ Number
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Fri Jan 09, 2004 4:43 pm Reply with quote Back to top

Old news. And, it only worked where MySQL v4.x is being used.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
Luth
New Member
New Member


Joined: Jan 05, 2004
Posts: 3

PostPosted: Fri Jan 09, 2004 7:03 pm Reply with quote Back to top

So this is only an issue with MySQL v4.x and below? Above that version? Or strickly v4.x? Could you please clarify this a bit. Old news to you but new to me as I have just started toying with the nuke site builder. I would like to know if my efforts are in vain...


Last edited by Luth on Fri Jan 09, 2004 8:01 pm; edited 1 time in total
View user's profile Send private message
TheosEleos
Life Cycles Becoming CPU Cycles


Joined: Sep 18, 2003
Posts: 960
Location: Missouri

PostPosted: Fri Jan 09, 2004 7:34 pm Reply with quote Back to top

^^Cheesehead friend of mine.
View user's profile Send private message Visit poster's website AIM Address ICQ Number
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Fri Jan 09, 2004 9:22 pm Reply with quote Back to top

4.x only, to my understanding. Many of us have tried to replicate the 'exploit' and have not been able to.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
Luth
New Member
New Member


Joined: Jan 05, 2004
Posts: 3

PostPosted: Fri Jan 09, 2004 10:22 pm Reply with quote Back to top

Gotcha, thx

Cool
View user's profile Send private message
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum