Back

CVE-2004-2295

SQL injection vulnerability in the Reviews module in PHP-Nuke 6.0 to 7.3 allows remote attackers to execute arbitrary SQL commands via the order parameter.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

GitHub Security Advisory GHSA-4m8x-fc8r-wmqm

SQL injection vulnerability in the Reviews module in PHP-Nuke 6.0 to 7.3 allows remote attackers...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.28%

Top 32% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub