CVE-2001-1025

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/08/2001
Last modified:
03/04/2025

Description

PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:francisco_burzi:php-nuke:5.0:*:*:*:*:*:*:*
cpe:2.3:a:francisco_burzi:php-nuke:5.0.1:*:*:*:*:*:*:*