SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote attackers to obtain the administrator password via the c_mid parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/15080
https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-0266