Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown

CVE-2010-5083

Disclosure Date: February 14, 2012 (last updated October 04, 2023)
SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter in an Add action to modules.php.
0
Attacker Value
Unknown

CVE-2011-3784

Disclosure Date: September 24, 2011 (last updated October 04, 2023)
Francisco Burzi PHP-Nuke 8.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by themes/Odyssey/theme.php and certain other files.
0
Attacker Value
Unknown

CVE-2009-1842

Disclosure Date: June 01, 2009 (last updated October 04, 2023)
SQL injection vulnerability in main/tracking/userLog.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header.
0
Attacker Value
Unknown

CVE-2007-6376

Disclosure Date: December 15, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in autohtml.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the filename parameter, a different vector than CVE-2006-4190. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2007-4212

Disclosure Date: August 08, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Search Module in PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via a trailing "<" instead of a ">" in (1) the onerror attribute of an IMG element, (2) the onload attribute of an IFRAME element, or (3) redirect users to other sites via the META tag.
0
Attacker Value
Unknown

CVE-2007-1449

Disclosure Date: March 14, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.
0
Attacker Value
Unknown

CVE-2007-1450

Disclosure Date: March 14, 2007 (last updated October 04, 2023)
SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Top or News module via the lang parameter.
0
Attacker Value
Unknown

CVE-2006-5494

Disclosure Date: October 25, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB module for PHP-Nuke allow remote attackers to execute arbitrary PHP code via a URL in the (1) adminpath or (2) basepath parameters. NOTE: this issue might overlap CVE-2006-6795.
0
Attacker Value
Unknown

CVE-2004-1914

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL commands via the eid parameter.
0
Attacker Value
Unknown

CVE-2004-1913

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject arbitrary web script or HTML via the eid parameter.
0