Francisco Burzi

Php-nuke

94 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.02%
  • Published 31.12.2003 05:00:00
  • Last modified 03.04.2025 01:03:51

Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to the getit function or the (2) min parameter to the search function.

Exploit
  • EPSS 0.12%
  • Published 31.12.2003 05:00:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web script or HTML via the user_avatar parameter.

Exploit
  • EPSS 0.02%
  • Published 31.12.2003 05:00:00
  • Last modified 03.04.2025 01:03:51

SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module.

Exploit
  • EPSS 0.01%
  • Published 31.12.2003 05:00:00
  • Last modified 03.04.2025 01:03:51

PHP-Nuke 7.0 allows remote attackers to obtain the installation path via certain characters such as (1) ", (2) ', or (3) > in the search field, which reveals the path in an error message.

Exploit
  • EPSS 0.03%
  • Published 31.12.2003 05:00:00
  • Last modified 03.04.2025 01:03:51

The Web_Links module in PHP-Nuke 6.0 through 6.5 final allows remote attackers to obtain the full web server path via an invalid cid parameter that is non-numeric or null, which leaks the pathname in an error message.

  • EPSS 0.02%
  • Published 16.06.2003 04:00:00
  • Last modified 03.04.2025 01:03:51

Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php...

  • EPSS 0.02%
  • Published 09.06.2003 04:00:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in the Statistics module for PHP-Nuke 6.0 and earlier allows remote attackers to insert arbitrary web script via the year parameter.

Exploit
  • EPSS 0.03%
  • Published 31.12.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

sql_layer.php in PHP-Nuke 5.4 and earlier does not restrict access to debugging features, which allows remote attackers to gain SQL query information by setting the sql_debug parameter to (1) index.php and (2) modules.php.

Exploit
  • EPSS 0.15%
  • Published 31.12.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in PHP-Nuke 6.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.

  • EPSS 0.09%
  • Published 12.11.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

SQL injection vulnerability in PHP-Nuke before 6.0 allows remote authenticated users to modify the database and gain privileges via the "bio" argument to modules.php.