PHP-Nuke Search Module SQL Injection

  Bookmark
 and Share

PHP-Nuke is a content manager. The Search module is exposed to an SQL injection issue because it fails to sufficiently sanitize user-supplied data to the "sid" parameter before using it in an SQL query. PHP-Nuke Search module versions 8.1.0.3.5b and earlier are affected.

Ref: http://www.securityfocus.com/bid/45165

10.50.44 - CVE: Not Available
Platform: Web Application - SQL Injection