← Vulnerability feed

Vulnerability record · CVE-2007-1450 · published 14 March 2007

CVE-2007-1450: Phpnuke php-nuke vulnerability

PPhpnuke · Php Nuke

SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Top or News module via the lang parameter.

7.5 CVSS 2.0 High EPSS 1.0% · top 38.6%
7.5CVSS 2.0 base score
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Top or News module via the lang parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-1450 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-30177Phpnuke php-nuke sql injection vulnerabilityThere is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execution. This occurs because the …EPSS 2.4%8.8CVE-2004-1842Phpnuke php-nuke cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img ta…EPSS 1.7%7.5CVE-2014-3934Phpnuke php-nuke sql injection vulnerabilitySQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL commands via the topics[] par…EPSS 2.2%7.5CVE-2010-5083Phpnuke php-nuke sql injection vulnerabilitySQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter …EPSS 1.1%7.5CVE-2011-1480Phpnuke php-nuke sql injection vulnerabilitySQL injection vulnerability in admin.php in the administration backend in Francisco Burzi PHP-Nuke 8.0 and earlier allows remote attackers to execute…EPSS 1.2%7.5CVE-2009-1842Phpnuke php-nuke sql injection vulnerabilitySQL injection vulnerability in main/tracking/userLog.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands vi…EPSS 0.96%7.5CVE-2008-6728Phpnuke php-nuke sql injection vulnerabilitySQL injection vulnerability in the Sections module in PHP-Nuke, probably before 8.0, allows remote attackers to execute arbitrary SQL commands via th…EPSS 1.1%7.5CVE-2008-2020E107 vulnerabilityThe CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) phpMyBitT…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2007-1450), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.