Back

CVE-2006-0679

SQL injection vulnerability in index.php in the Your_Account module in PHP-Nuke 7.8 and earlier allows remote attackers to execute arbitrary SQL commands via the username variable (Nickname field).

Published: Feb 16, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
francisco_burzi php-nuke_ev 7.8

GitHub Security Advisory GHSA-gv69-cv5h-2qf5

SQL injection vulnerability in index.php in the Your_Account module in PHP-Nuke 7.8 and earlier...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 3.67%

Top 11% most likely to be exploited

Threat Score 31.1 / 100

Data Sources

NVD EPSS GitHub