Bugtraq mailing list archives

PHP-Nuke x.x AND PostNuke SQL Injection


From: Pedro Inacio <pedro.inacio () ptnix com>
Date: 26 Sep 2002 18:48:02 -0000



Hello again,

just to say that PostNuke ( fork of PHP-Nuke ) is vulnerable to the same
bugs
AND
it is possible to inject different SQL code in order to do other "funny" 
but "dangerous" things.

Note to the guys of those projects:
Filter those URL entries!!!

Cheers,

Pedro Inacio


Current thread: