PHPNuke Category Parameter SQL Injection Vulnerability

Posted on Sunday, February 15, 2004 @ 14:19:00 CST in Security
by chatserv

Patch your search module:
under /* Category Selection */
add:
$category = intval($category);
and change:
$categ = "AND catid=$category ";
to:
$categ = "AND catid='$category' ";
 
 
click Related        click Share
 
News ©

Site Info

Last SeenLast Seen
  • vashd1
  • neralex
Server TrafficServer Traffic
  • Total: 514,139,903
  • Today: 9,130
Server InfoServer Info
  • May 01, 2025
  • 02:34 am CDT