- EPSS 5.9%
- Veröffentlicht 30.12.2008 20:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Nukedit 4.9.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for database/dbsite.mdb.
CVE-2008-5582
- EPSS 0.41%
- Veröffentlicht 15.12.2008 18:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in utilities/login.asp in Nukedit 4.9.x, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the email parameter.
CVE-2007-4052
- EPSS 0.61%
- Veröffentlicht 30.07.2007 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in utilities/login.asp in nukedit 4.9.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the email parameter. NOTE: the provenance of this information is unknown; the details are...
CVE-2007-2432
- EPSS 1.03%
- Veröffentlicht 02.05.2007 10:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in utilities/search.asp in nukedit 4.9.7b allows remote attackers to inject arbitrary web script or HTML via the terms parameter. NOTE: the provenance of this information is unknown; the details are obtained ...
CVE-2006-2737
- EPSS 9.62%
- Veröffentlicht 01.06.2006 10:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
utilities/register.asp in Nukedit 4.9.6 and earlier allows remote attackers to create new users as part of arbitrary groups, including the administrative group, via a modified groupid parameter when creating a user via the addDB action.