Vulnerability Description
sql_layer.php in PHP-Nuke 5.4 and earlier does not restrict access to debugging features, which allows remote attackers to gain SQL query information by setting the sql_debug parameter to (1) index.php and (2) modules.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Francisco Burzi | Php-Nuke | 1.0 |
References
- http://www.securityfaq.com/unixfocus/5OP041P6BE.htmlExploitURL Repurposed
- http://www.securityfocus.com/bid/3906Exploit
- http://www.securityfaq.com/unixfocus/5OP041P6BE.htmlExploitURL Repurposed
- http://www.securityfocus.com/bid/3906Exploit
FAQ
What is CVE-2002-2032?
CVE-2002-2032 is a vulnerability with a CVSS score of 5.0 (MEDIUM). sql_layer.php in PHP-Nuke 5.4 and earlier does not restrict access to debugging features, which allows remote attackers to gain SQL query information by setting the sql_debug parameter to (1) index.ph...
How severe is CVE-2002-2032?
CVE-2002-2032 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-2032?
Check the references section above for vendor advisories and patch information. Affected products include: Francisco Burzi Php-Nuke.