PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T04:44:06.627Z
Reserved: 2002-01-31T00:00:00
Link: CVE-2001-1025

No data.

Status : Modified
Published: 2001-08-31T04:00:00.000
Modified: 2024-11-20T23:36:41.620
Link: CVE-2001-1025

No data.