CVE-2004-1929 describes a SQL injection vulnerability within the bblogin function of functions.php in PHP-Nuke versions 6.x through 7.2. This flaw allows remote attackers to bypass authentication and gain unauthorized access by injecting base64-encoded SQL code into the 'user' parameter. The vulnerability carries a CVSS score of 7.5, indicating high severity. It is easily exploitable over the network with low attack complexity and no authentication required, potentially leading to partial compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation in the wild (KEV list), exploit code is publicly available via ExploitDB. Despite this, there is minimal community discussion or media coverage surrounding this particular CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.5CPE matchmatch criteria | cpe:2.3:a:francisco_burzi:php-nuke:5.5:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:francisco_burzi:php-nuke:6.0:*:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:a:francisco_burzi:php-nuke:6.5:*:*:*:*:*:*:* | ||
6.5_beta1CPE matchmatch criteria | cpe:2.3:a:francisco_burzi:php-nuke:6.5_beta1:*:*:*:*:*:*:* | ||
6.5_finalCPE matchmatch criteria | cpe:2.3:a:francisco_burzi:php-nuke:6.5_final:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.