PHP-Nuke / PHP-Nuke
22 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-30177 | There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execution. This occurs because the U.S. state… | CRITICAL | 9.8 | Apr 7, 2021 |
| CVE-2014-3934 | SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL commands via the topics[] parameter to… | HIGH | 7.5 | Jun 2, 2014 |
| CVE-2010-5083 | SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter in an Add… | HIGH | 7.5 | Feb 14, 2012 |
| CVE-2011-3784 | Francisco Burzi PHP-Nuke 8.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path i… | MEDIUM | 5.0 | Sep 24, 2011 |
| CVE-2011-1482 | Multiple cross-site request forgery (CSRF) vulnerabilities in mainfile.php in Francisco Burzi PHP-Nuke 8.0 and earlier allow remote attackers to hijack the aut… | MEDIUM | 6.8 | Jun 21, 2011 |
| CVE-2011-1481 | Multiple cross-site scripting (XSS) vulnerabilities in Francisco Burzi PHP-Nuke 8.0 and earlier allow remote attackers to inject arbitrary web script or HTML v… | MEDIUM | 4.3 | Jun 21, 2011 |
| CVE-2011-1480 | SQL injection vulnerability in admin.php in the administration backend in Francisco Burzi PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary… | HIGH | 7.5 | Jun 21, 2011 |
| CVE-2009-1842 | SQL injection vulnerability in main/tracking/userLog.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the HTTP… | HIGH | 7.5 | Jun 1, 2009 |
| CVE-2008-6728 | SQL injection vulnerability in the Sections module in PHP-Nuke, probably before 8.0, allows remote attackers to execute arbitrary SQL commands via the artid pa… | HIGH | 7.5 | Apr 20, 2009 |
| CVE-2008-3573 | The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the ts_random value) within the… | MEDIUM | 5.0 | Aug 10, 2008 |
| CVE-2008-2020 | The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) phpMyBitTorrent 1.2… | HIGH | 7.5 | Apr 30, 2008 |
| CVE-2003-1340 | Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 5.6 and 6.5 allow remote authenticated users to execute arbitrary SQL commands via (1) a uid… | MEDIUM | 6.5 | Oct 1, 2007 |
| CVE-2007-4212 | Multiple cross-site scripting (XSS) vulnerabilities in the Search Module in PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via a traili… | MEDIUM | 4.3 | Aug 8, 2007 |
| CVE-2007-1520 | The cross-site request forgery (CSRF) protection in PHP-Nuke 8.0 and earlier does not ensure the SERVER superglobal is an array before validating the HTTP_REFE… | MEDIUM | 6.8 | Mar 20, 2007 |
| CVE-2007-1519 | Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke 8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the quer… | MEDIUM | 4.3 | Mar 20, 2007 |
| CVE-2007-1450 | SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Top or News module via… | HIGH | 7.5 | Mar 14, 2007 |
| CVE-2007-1449 | Directory traversal vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the lang pa… | MEDIUM | 4.3 | Mar 14, 2007 |
| CVE-2006-5525 | Incomplete blacklist vulnerability in mainfile.php in PHP-Nuke 7.9 and earlier allows remote attackers to conduct SQL injection attacks via (1) "/**/UNION " or… | MEDIUM | 5.1 | Oct 26, 2006 |
| CVE-2006-5494 | Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB module for PHP-Nuke allow remote attackers… | HIGH | 7.5 | Oct 25, 2006 |
| CVE-2004-1842 | Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a U… | HIGH | 8.8 | May 10, 2005 |
| CVE-2005-1028 | PHP-Nuke 6.x through 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) index.php with the forum_admin parameter set, (2)… | MEDIUM | 5.0 | Apr 9, 2005 |
| CVE-2001-0899 | Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variable. | HIGH | 7.5 | Jun 25, 2002 |
Showing 1 to 22 of 22 CVEs