PHPNuke Admin Cookie Variable SQL...

- AV AC AU C I A
发布: 2003-02-19
修订: 2025-04-13

It has been reported that the 'admin' Cookie Variable used by PHPNuke during the authentication process is vulnerable to an SQL injection attack. PHPNuke, in some cases, does not sufficiently sanitize Cookie based data which is used when constructing SQL queries during the authentication process. As a result, attackers may supply malicious cookie tokens to manipulate the structure and logic of SQL queries. This may result in unauthorized operations being performed on the underlying database. This issue may be exploited to cause sensitive information to be disclosed to a remote attacker.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息