Create an account    
 home  
 
Web www.thaihealth.net
  You are here:> home>topics> Linux&NUKE Security > phpNUKE security hole in News Module (up to Ver 7.9) ©
phpNUKE security hole in News Module (up to Ver 7.9)
Posted on Wednesday, November 29 @ 18:23:53 GMT+7 by webmaster

Linux&NUKE Security Paisterist has discovered two vulnerabilities in PHP-Nuke, which can be exploited by malicious people to conduct SQL injection attacks....(from http://secunia.com/advisories/23128/)I am not sure the sentinel will be protective or not

Input passed to the "sid" parameter in modules/News/index.php from modules.php is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

Successful exploitation allows retrieval of administrator usernames and password hashes, but requires that "magic_quotes_gpc" is disabled and that the attacker knows the prefix for the database tables.

The vulnerabilities are confirmed in version 7.9. Other versions may also be affected.

Solution: Edit the source code to ensure that input is properly sanitised.

Set "magic_quotes_gpc" in php.ini to On.

Use another product.


blog this


blog this

More about linuxsecure
· phpNUKE security hole in News Module (up to Ver 7.9)2006-11-29 18:23:53
· security fixes for cross site scripting in nuke6.0-7.02004-03-26 01:15:24
· important security fix in admin.php2004-03-26 00:14:00
· upgrade Apache to 2.0.48 lastest one2003-12-20 16:25:11

Comment Post
1  by
on Saturday, March 15 @ 05:46:08 GMT+7
< href="http://www.jsoftj.com/">URL blocked by staff جي سوف

Read the rest of this comment...


2  by
on Sunday, March 16 @ 20:12:51 GMT+7
< href="http://f.jsoftj.com/">URL blocked by staff منتديا&

Read the rest of this comment...


3  by kjhg
on Thursday, June 05 @ 23:37:42 GMT+7
< href="http://wardh.al-kaon.com/">URL blocked by staff منتدي

Read the rest of this comment...




Your Name:

[ New User ]

Subject:


Comment:

Allowed HTML:
<b> <i> <a> <em> <br> <strong> <blockquote> <tt> <li> <ol> <ul>
Security code:



T news tweak
 

       Sponsored Links
       Related Links
· More about Linux&NUKE Security
· News by webmaster


Most read story about Linux&NUKE Security:
 Top tools for Linux(19831)

       Article Rating
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Excellent
Very Good
Good
Regular
Bad


       Options

 Printer Friendly  Printer Friendly

 Send to a Friend  Send to a Friend

Associated Topics

phpNUKEPHPNUKE 8.1 has been released
Thainuke.net has been changed to thainuke.org
Basic PHP-courses(THAI) 11 september by thainukeclub.com
''You can't access this file dir.....'' why?
fix to correctly display user in non-english site-NUKE7.7



News ©

เล่นเกมส์ arcade games free!

main sitethaihealth | home | forums | downloads | topics

Seo from our desk thai seo
Web site engine code is Copyright © 2003 by PHP-Nuke.Copyright 2007 Thaihealth and pattaya doctor
Page Generation: 0.261 Seconds

Theme developed by WebDesignHQ.com Modified By DoctorNUKE