Security Advisory

CVE-2003-1210

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2005-05-19 04:00:00
Last updated 2024-08-08 02:19:45
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to the getit function or the (2) min parameter to the search function.