Vulnerability record · CVE-2007-1061 · published 22 February 2007
CVE-2007-1061: PHP-Nuke index.php SQL injection via HTTP Referer header
FFrancisco Burzi · Php Nuke
PHP-Nuke 8.0 Final and earlier contains a SQL injection flaw in index.php that is reachable when the "HTTP Referers" block is enabled. The HTTP_REFERER value is passed into a SQL query without adequate sanitization, letting a remote attacker inject arbitrary SQL commands. Because the Referer header is attacker-controlled and the vulnerable code path is a normal page request, this is a low-effort injection against any site with that block turned on.
Description
SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" block is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header (HTTP_REFERER variable).
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote SQL injection with public exploit code and a very high EPSS score, though exploitation depends on the HTTP Referers block being enabled.
What it is
PHP-Nuke 8.0 Final and earlier contains a SQL injection flaw in index.php that is reachable when the "HTTP Referers" block is enabled. The HTTP_REFERER value is passed into a SQL query without adequate sanitization, letting a remote attacker inject arbitrary SQL commands. Because the Referer header is attacker-controlled and the vulnerable code path is a normal page request, this is a low-effort injection against any site with that block turned on.
Impact
An attacker can execute arbitrary SQL commands against the PHP-Nuke database, potentially reading, modifying or deleting data and, depending on database privileges, escalating to further compromise. The CVSS 2.0 vector rates partial confidentiality, integrity and availability impact.
Attack surface
Reached remotely over the network through a standard HTTP request to index.php; the injected payload travels in the Referer header. No authentication is required, and no user interaction beyond the attacker's own request is needed, though the HTTP Referers block must be enabled for the vulnerable code to run.
Exploitation
Not listed in CISA KEV, but EPSS is high at 0.608 (99.1st percentile), and a public Exploit-DB entry (3346) exists, indicating exploit code is publicly available. No ransomware group is documented as using it.
What to do
- Upgrade or patch PHP-Nuke to a version later than 8.0 Final, or apply the vendor fix referenced in the Secunia advisory.
- If the HTTP Referers block is not required, disable it to remove the vulnerable code path.
- Use parameterized queries or strict input validation for the Referer value in any custom or retained code.
- Run the PHP-Nuke database account with least privilege to limit the impact of successful injection.
- Place a WAF or reverse proxy rule in front of index.php to reject SQL metacharacters in the Referer header.
Detection
- Search web and database logs for SQL syntax or UNION/boolean patterns in the Referer header on requests to index.php.
- Alert on Referer values containing quotes, comment markers or SQL keywords that are abnormal for legitimate browsing.
- Monitor database error messages or unexpected query failures correlated with index.php requests.
- Review PHP-Nuke configuration to confirm whether the HTTP Referers block is enabled on exposed instances.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-1061 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-1061), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.