CVE-2001-1025

critical

Description

PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php.

References

https://euvd.enisa.europa.eu/vulnerability/EUVD-2001-1006

http://www.securityfocus.com/bid/3149

http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0019.html

Details

Source: Mitre, NVD

Published: 2001-08-31

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00073