PHP-Nuke versions 6.x through 7.1.0 allow for link inclusions that can force an administrator to unknowingly add a superuser.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/32925/waraxe-2004-SA008.txt
Source: https://packetstormsecurity.com/files/32925/waraxe-2004-SA008.txt.html