ID

VAR-200108-0041


CVE

CVE-2001-1025


TITLE

PHP-Nuke Remotely SQL Query tampering Vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200108-193

DESCRIPTION

PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php. PHP-Nuke reportedly contains a vulnerability introduced in a new feature which may permit remote attackers to execute almost arbitrary SQL queries. In version 5.x of PHP-Nuke, the administrator can set an arbitrary prefix for the database table names. Because it is a prefix for PHP-Nuke tables, this variable is included in many SQL queries used by PHP-Nuke. Vulnerabilities exist in PHP-Nuke 5.x versions

Trust: 1.26

sources: NVD: CVE-2001-1025 // BID: 3149 // VULHUB: VHN-3830

AFFECTED PRODUCTS

vendor:francisco burzimodel:php-nukescope:eqversion:5.0

Trust: 1.6

vendor:francisco burzimodel:php-nukescope:eqversion:5.0.1

Trust: 1.6

vendor:franciscomodel:burzi php-nukescope:eqversion:5.0.1

Trust: 0.3

vendor:franciscomodel:burzi php-nukescope:eqversion:5.0

Trust: 0.3

sources: BID: 3149 // CNNVD: CNNVD-200108-193 // NVD: CVE-2001-1025

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2001-1025
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200108-193
value: CRITICAL

Trust: 0.6

VULHUB: VHN-3830
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2001-1025
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-3830
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-3830 // CNNVD: CNNVD-200108-193 // NVD: CVE-2001-1025

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2001-1025

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200108-193

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-200108-193

EXTERNAL IDS

db:NVDid:CVE-2001-1025

Trust: 2.0

db:BIDid:3149

Trust: 2.0

db:CNNVDid:CNNVD-200108-193

Trust: 0.7

db:VULNWATCHid:20010803 [VULNWATCH] 3 PHPNUKE BUGS (2 POSSIBLY LEAD TO ADMIN PRIVS)

Trust: 0.6

db:VULHUBid:VHN-3830

Trust: 0.1

sources: VULHUB: VHN-3830 // BID: 3149 // CNNVD: CNNVD-200108-193 // NVD: CVE-2001-1025

REFERENCES

url:http://www.securityfocus.com/bid/3149

Trust: 1.7

url:http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0019.html

Trust: 1.7

sources: VULHUB: VHN-3830 // CNNVD: CNNVD-200108-193 // NVD: CVE-2001-1025

CREDITS

Discovered by kill-9@modernhacker.com.

Trust: 0.9

sources: BID: 3149 // CNNVD: CNNVD-200108-193

SOURCES

db:VULHUBid:VHN-3830
db:BIDid:3149
db:CNNVDid:CNNVD-200108-193
db:NVDid:CVE-2001-1025

LAST UPDATE DATE

2024-08-14T14:29:38.695000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-3830date:2008-09-05T00:00:00
db:BIDid:3149date:2009-07-11T07:56:00
db:CNNVDid:CNNVD-200108-193date:2005-10-20T00:00:00
db:NVDid:CVE-2001-1025date:2008-09-05T20:25:29.957

SOURCES RELEASE DATE

db:VULHUBid:VHN-3830date:2001-08-31T00:00:00
db:BIDid:3149date:2001-08-03T00:00:00
db:CNNVDid:CNNVD-200108-193date:2001-08-31T00:00:00
db:NVDid:CVE-2001-1025date:2001-08-31T04:00:00