Description
|
|
A vulnerability has been identified in NukeScripts NukeSentinel, which could be exploited by attackers to execute arbitrary SQL queries. This issue is caused by an input validation error in the "write_ban()" [includes/nukesentinel.php] function that does not validate the "admin" cookie parameter before being passed to the "abget_admin()" function and used in SQL statements, which could be exploited by malicious people to conduct SQL injection attacks.
|