PHP-Nuke Personal Menu Script Insertion and SQL Injection

Posted on Wednesday, February 22, 2006 @ 11:31:51 UTC in Security
by Raven

SECUNIA ADVISORY ID: SA18972

VERIFY ADVISORY

CRITICAL: Moderately critical
IMPACT: Cross Site Scripting, Manipulation of data

If you are using NukeSentinel(tm) you should be protected from this exploit.
 
 
click Related        click Share
 
 

Re: PHP-Nuke Personal Menu Script Insertion and SQL Injection (Score: 1)
by evaders99 on Wednesday, February 22, 2006 @ 19:32:00 UTC

(User Info | Send a Message) http://www.swrebellion.com

Please note this thread:
Patched 3.2 URGENT POST RELEASE FIXES
http://www.nukefixes.com/ftopic-2196-0-days0-orderasc-.html

Re: PHP-Nuke Personal Menu Script Insertion and SQL Injection (Score: 1)
by hitwalker
on Thursday, February 23, 2006 @ 08:28:01 UTC
(User Info | Send a Message)

patch...patch....patch....patch...patch....patch....patch...patch....patch....patch...patch....patch....
i wouldnt be suprised if one day people will kick out phpnuke for something else...

patch after patch...where is this gonna end?
takes the fun out of running a website.

Re: PHP-Nuke Personal Menu Script Insertion and SQL Injection (Score: 1)
by evaders99
on Thursday, February 23, 2006 @ 17:56:43 UTC
(User Info | Send a Message) http://www.swrebellion.com

Well we can always blame FB for writing such insecure code ... hackers for exploiting them... Microsoft for being the prime example of what happens when you don't patch...

:)

 
News ©

Site Info

Last SeenLast Seen
  • vashd1
  • kguske
Server TrafficServer Traffic
  • Total: 482,528,559
  • Today: 7,456
Server InfoServer Info
  • Apr 26, 2024
  • 04:28 am UTC