← Vulnerability feed

Vulnerability record · CVE-2007-1061 · published 22 February 2007

CVE-2007-1061: PHP-Nuke index.php SQL injection via HTTP Referer header

FFrancisco Burzi · Php Nuke

PHP-Nuke 8.0 Final and earlier contains a SQL injection flaw in index.php that is reachable when the "HTTP Referers" block is enabled. The HTTP_REFERER value is passed into a SQL query without adequate sanitization, letting a remote attacker inject arbitrary SQL commands. Because the Referer header is attacker-controlled and the vulnerable code path is a normal page request, this is a low-effort injection against any site with that block turned on.

6.8 CVSS 2.0 Medium EPSS 62% · top 0.9%
6.8CVSS 2.0 base score
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" block is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header (HTTP_REFERER variable).

AV:N/AC:M/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote SQL injection with public exploit code and a very high EPSS score, though exploitation depends on the HTTP Referers block being enabled.

What it is

PHP-Nuke 8.0 Final and earlier contains a SQL injection flaw in index.php that is reachable when the "HTTP Referers" block is enabled. The HTTP_REFERER value is passed into a SQL query without adequate sanitization, letting a remote attacker inject arbitrary SQL commands. Because the Referer header is attacker-controlled and the vulnerable code path is a normal page request, this is a low-effort injection against any site with that block turned on.

Impact

An attacker can execute arbitrary SQL commands against the PHP-Nuke database, potentially reading, modifying or deleting data and, depending on database privileges, escalating to further compromise. The CVSS 2.0 vector rates partial confidentiality, integrity and availability impact.

Attack surface

Reached remotely over the network through a standard HTTP request to index.php; the injected payload travels in the Referer header. No authentication is required, and no user interaction beyond the attacker's own request is needed, though the HTTP Referers block must be enabled for the vulnerable code to run.

Exploitation

Not listed in CISA KEV, but EPSS is high at 0.608 (99.1st percentile), and a public Exploit-DB entry (3346) exists, indicating exploit code is publicly available. No ransomware group is documented as using it.

What to do

  • Upgrade or patch PHP-Nuke to a version later than 8.0 Final, or apply the vendor fix referenced in the Secunia advisory.
  • If the HTTP Referers block is not required, disable it to remove the vulnerable code path.
  • Use parameterized queries or strict input validation for the Referer value in any custom or retained code.
  • Run the PHP-Nuke database account with least privilege to limit the impact of successful injection.
  • Place a WAF or reverse proxy rule in front of index.php to reject SQL metacharacters in the Referer header.

Detection

  • Search web and database logs for SQL syntax or UNION/boolean patterns in the Referer header on requests to index.php.
  • Alert on Referer values containing quotes, comment markers or SQL keywords that are abnormal for legitimate browsing.
  • Monitor database error messages or unexpected query failures correlated with index.php requests.
  • Review PHP-Nuke configuration to confirm whether the HTTP Referers block is enabled on exposed instances.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-1061 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-3016Francisco burzi php-nuke vulnerabilityMultiple unspecified vulnerabilities in the WYSIWYG editor in PHP-Nuke before 7.9 Final have unknown impact and attack vectors.EPSS 1.4%10.0CVE-2001-1025Francisco burzi php-nuke vulnerabilityPHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not alre…EPSS 2.8%10.0CVE-2001-0320Francisco burzi php-nuke vulnerabilitybb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting …EPSS 2.6%7.5CVE-2007-6376Francisco burzi php-nuke path traversal vulnerabilityDirectory traversal vulnerability in autohtml.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to include and execute arbitrary local file…EPSS 2.6%7.5CVE-2007-0372Francisco burzi php-nuke vulnerabilityMultiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 7.9 allow remote attackers to execute arbitrary SQL commands via (1) the active pa…EPSS 4.0%7.5CVE-2007-0309Francisco burzi php-nuke vulnerabilitySQL injection vulnerability in blocks/block-Old_Articles.php in Francisco Burzi PHP-Nuke 7.9 and earlier, when register_globals is enabled and magic_…EPSS 4.7%7.5CVE-2006-6234Francisco burzi php-nuke vulnerabilityMultiple SQL injection vulnerabilities in the Content module in PHP-Nuke 6.0, and possibly other versions, allow remote attackers to execute arbitrar…EPSS 2.0%7.5CVE-2006-6200Francisco burzi php-nuke vulnerabilityMultiple SQL injection vulnerabilities in the (1) rate_article and (2) rate_complete functions in modules/News/index.php in the News module in Franci…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2007-1061), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.