HTTP: PHP-Nuke Administrator Password Enumeration

This signature detects attempts to exploit a known vulnerability in modules.php that ships with PHPNuke. Attackers can embed SQL statements in a maliciously crafted query to modules.php script to obtain the administrator password for PHPNuke.

Extended Description

An attacker could gain information that will allow administrator access to the PHPNuke system.

References

URL: http://CGIshield.com

Short Name
HTTP:PHP:PHPNUKE:ADMIN-GUESS
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Administrator Enumeration PHP-Nuke Password
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?