Home » Hacking News » PHP-Nuke banner manager password disclosure
PHP-Nuke banner manager password disclosure
by Nikola Strahija on March 29th, 2003 A vulnerability has been found in PHPNuke that allows a remote attacker to send a string through the script and thus manipulate some parts of the database.
Vulnerable:
PHP-Nuke 6.5, RC1, RC2, RC3
PHP-Nuke 6.0
PHP-Nuke 5.6
Solution:
Un-confirmed patch:
- http://www.frogsecure.com/tutos/PHP-Nuke-News.txt
Discovered by:
Frog Man, leseulfrog (at) hotmail.com
References:
Frog Man's site:
- http://www.phpsecure.info