PHPNuke versions greater than 6.9 are susceptible to SQL injection attacks that allow a remote attacker to get an administrator’s hash to achieve to administrator access.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/32658/phpnukeSQL.txt
Source: https://packetstormsecurity.com/files/32658/phpnukeSQL.txt.html