peter bassill · operator
$ cve CVE-2005-0997 JSON

CVE-2005-0997 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 1.4% (pctl 72)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 7.6 allow remote attackers to execute arbitrary SQL commands via (1) the email or url parameters in the Add function, (2) the url parameter in the modifylinkrequestS function, (3) the orderby or min parameters in the viewlink function, (4) the orderby, min, or show parameters in the search function, or (5) the ratenum parameter in the MostPopular function.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS1.42% — more likely to be exploited than 72% of all CVEs
On CISA KEVno
Public exploityes
Published2005-05-02
Last modified2026-06-16

Affected (1)

VendorProduct
francisco burziphp-nuke

Public exploits

SourceTitleDate
exploit-dbPHP-Nuke 7.6 Web_Links Module - Multiple SQL Injections2005-04-07

References

→ the Explorer  ·  watch your stack  ·  NVD