CVE-2011-1480

SQL injection vulnerability in admin.php in the administration backend in Francisco Burzi PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands via the chng_uid parameter.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
VendorProductVersion
phpnukephp-nuke
𝑥
≤ 8.0
phpnukephp-nuke
5.0
phpnukephp-nuke
5.0.1
phpnukephp-nuke
5.1
phpnukephp-nuke
5.2
phpnukephp-nuke
5.3
phpnukephp-nuke
5.3.1
phpnukephp-nuke
5.4
phpnukephp-nuke
5.5
phpnukephp-nuke
5.6
phpnukephp-nuke
6.0
phpnukephp-nuke
6.5
phpnukephp-nuke
6.6
phpnukephp-nuke
6.7
phpnukephp-nuke
6.8
phpnukephp-nuke
6.9
phpnukephp-nuke
7.0
phpnukephp-nuke
7.1
phpnukephp-nuke
7.2
phpnukephp-nuke
7.3
phpnukephp-nuke
7.4
phpnukephp-nuke
7.5
phpnukephp-nuke
7.6
phpnukephp-nuke
7.7
phpnukephp-nuke
7.8
phpnukephp-nuke
7.9
𝑥
= Vulnerable software versions