Back

CVE-2004-2000

SQL injection vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL via the (1) orderby or (2) sid parameters to modules.php.

Published: May 5, 2004 Modified: Jun 16, 2026

CVSS Metrics

GitHub Security Advisory GHSA-6979-7cwq-22m2

SQL injection vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.87%

Top 22% most likely to be exploited

Threat Score 30.6 / 100

Data Sources

NVD EPSS GitHub