CVE-2004-1932
SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter.
- Affected products
- Php-Nuke
- Francisco Burzi Php-nuke
- = 6.0, 6.5, 6.5_beta1, 6.5_final, 6.5_rc1, 6.5_rc2, 6.5_rc3, 6.6, 6.7, 6.9, 7.0, 7.0_final, 7.1, 7.2
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 2.1% (80th percentile)
- NVD status
- Modified
- Published
- 2005-05-10
CVE-2004-1932 at NVD
1 known exploit for CVE-2004-1932
Proof-of-concept code and exploit modules indexed by Sploitus