banners.php in PHP-Nuke 4.4 and earlier allows remote attackers to modify banner ad URLs by directly calling the Change operation, which does not require authentication.
https://exchange.xforce.ibmcloud.com/vulnerabilities/6342
http://www.securityfocus.com/bid/2544
http://phpnuke.org/download.php?dcategory=Fixes
http://archives.neohapsis.com/archives/bugtraq/2001-04/0017.html