Back
CVE-2002-1242
SQL injection vulnerability in PHP-Nuke before 6.0 allows remote authenticated users to modify the database and gain privileges via the "bio" argument to modules.php.
Published: Nov 12, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| francisco_burzi | php-nuke | 5.6 |
GitHub Security Advisory GHSA-vwr7-54pf-g58r
SQL injection vulnerability in PHP-Nuke before 6.0 allows remote authenticated users to modify...
References (12)
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0051.html
- http://marc.info/?l=bugtraq&m=103616324103171&w=2
- http://www.idefense.com/advisory/10.31.02c.txt Patch, Vendor Advisory
- http://www.iss.net/security_center/static/10516.php
- http://www.osvdb.org/6244
- http://www.securityfocus.com/bid/6088
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0051.html
- http://marc.info/?l=bugtraq&m=103616324103171&w=2
- http://www.idefense.com/advisory/10.31.02c.txt Patch, Vendor Advisory
- http://www.iss.net/security_center/static/10516.php
- http://www.osvdb.org/6244
- http://www.securityfocus.com/bid/6088
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
4.11%
Top 10% most likely to be exploited
Threat Score
31.2 / 100
Data Sources
NVD
EPSS
GitHub