CVE-2008-7132
- EPSS 0.25%
- Veröffentlicht 01.09.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in index.php in Nuked-Klan 1.3 beta allows remote attackers to inject arbitrary web script or HTML via the nuked_nude parameter. NOTE: the provenance of this information is unknown; the details are obtained s...
CVE-2007-6090
- EPSS 0.25%
- Veröffentlicht 22.11.2007 00:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in index.php in Nuked-Klan 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter. NOTE: the provenance of this information is unknown; the details are obtained solely fro...
CVE-2007-2556
- EPSS 5.36%
- Veröffentlicht 09.05.2007 18:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in Nuked-klaN 1.7.6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For (X_FORWARDED_FOR) HTTP header, as demonstrated by a request to the /nk/ URI.
CVE-2007-0083
- EPSS 1.01%
- Veröffentlicht 05.01.2007 11:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Nuked Klan 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a getURL statement in a .swf file, as demonstrated by "Remote Cookie Disclosure." NOTE: it...
CVE-2006-4480
- EPSS 0.44%
- Veröffentlicht 31.08.2006 21:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Incomplete blacklist vulnerability in the nk_CSS function in nuked.php in Nuked-Klan 1.7 SP4.3 allows remote attackers to bypass anti-XSS features and inject arbitrary web script or HTML via JavaScript in an attribute value that is not in the blackli...
- EPSS 0.48%
- Veröffentlicht 10.07.2006 20:05:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-site request forgery (CSRF) vulnerability in the del_block function in modules/Admin/block.php in Nuked-Klan 1.7.5 and earlier and 1.7 SP4.2 allows remote attackers to delete arbitrary "blocks" via a link with a modified bid parameter in a del_...
- EPSS 1.03%
- Veröffentlicht 28.03.2006 20:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
SQL injection vulnerability in the Calendar module in nuked-klan 1.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter to index.php.
CVE-2006-0506
- EPSS 0.53%
- Veröffentlicht 01.02.2006 23:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in index.php in Nuked-klaN 1.7 allows remote attackers to inject arbitrary web script or HTML via the letter parameter.
CVE-2005-3436
- EPSS 0.53%
- Veröffentlicht 02.11.2005 11:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in Nuked-Klan 1.7 allows remote attackers to inject arbitrary web script or HTML via the (1) Search module, (2) certain edit fields in Guestbook, (3) the title in the Forum module, and (4) Textbox.
CVE-2005-3305
- EPSS 3.49%
- Veröffentlicht 26.10.2005 01:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple SQL injection vulnerabilities in Nuked Klan 1.7 allow remote attackers to execute arbitrary SQL commands via the (1) forum_id or (2) thread_id parameter in the Forum file, (3) the link_id in the Links file, (4) the artid parameter in the Sec...