SQL injection vulnerability in the Kutub-i Sitte (KutubiSitte) 1.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the kid parameter in a hadisgoster action to modules.php.
References
Configurations
Information
Published : 2008-03-10 10:44
Updated : 2018-10-11 13:30
NVD link : CVE-2008-1219
Mitre link : CVE-2008-1219
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
phpnuke
- kutubisitte_component