VID |
21906 |
Severity |
30 |
Port |
80, ... |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
The Nucleus CMS, according to its version number, has an SQL injection vulnerability which exists in versions prior to 3.1. Nucleus CMS is an open-source content management system written by PHP. Nucleus CMS versions prior to 3.1 could allow a remote attacker to execute arbitrary SQL commands, caused by improper filtering of user-supplied input through the action.php script. This vulnerability could permit a remote attacker to pass malicious input to database queries, potentially resulting in data exposure, modification of the query logic, or even data modification or attacks against the database itself.
* Note: This check solely relied on the version number of Nucleus CMS on the remote Web server to assess this vulnerability, so this might be a false positive.
* References: http://archives.neohapsis.com/archives/bugtraq/2004-07/0288.html
* Platforms Affected: The Nucleus Group, Nucleus CMS versions prior to 3.1 Any operating system Any version |
Recommendation |
Upgrade to the latest version of Nucleus CMS (3.1 or later), available from the Nucleus Group Download Web site at http://nucleuscms.org/download.php |
Related URL |
(CVE) |
Related URL |
10798 (SecurityFocus) |
Related URL |
16811 (ISS) |
|