CVE

Id
3829  
CVE No.
CVE-2001-1025  
Status
Candidate  
Description
PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php.  
Phase
Proposed (20020131)  
Votes
ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  
Comments
Frech> XF:php-nuke-prefix-admin-access(6945)