Show filters
124 Total Results
Displaying 11-20 of 124
Sort by:
Attacker Value
Unknown
CVE-2008-2020
Disclosure Date: April 30, 2008 (last updated February 15, 2024)
The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) phpMyBitTorrent 1.2.2, (4) TorrentFlux 2.3, (5) e107 0.7.11, (6) WebZE 0.5.9, (7) Open Media Collectors Database (aka OpenDb) 1.5.0b4, and (8) Labgab 1.1 uses a code_bg.jpg background image and the PHP ImageString function in a way that produces an insufficient number of different images, which allows remote attackers to pass the CAPTCHA test via an automated attack using a table of all possible image checksums and their corresponding digit strings.
0
Attacker Value
Unknown
CVE-2008-1680
Disclosure Date: April 04, 2008 (last updated October 04, 2023)
PHP-Nuke Platinum 7.6.b.5 allows remote attackers to obtain configuration information via a direct request to maintenance/index.php, which reveals settings such as magic_quotes_gpc.
0
Attacker Value
Unknown
CVE-2008-1539
Disclosure Date: March 28, 2008 (last updated October 04, 2023)
SQL injection vulnerability in includes/dynamic_titles.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execute arbitrary SQL commands via the p parameter to modules.php for the Forums module.
0
Attacker Value
Unknown
CVE-2008-0906
Disclosure Date: February 22, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the Docum module in PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parameter in a viewarticle operation.
0
Attacker Value
Unknown
CVE-2008-0461
Disclosure Date: January 25, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the Search module in PHP-Nuke 8.0 FINAL and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the sid parameter in a comments action to modules.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-6376
Disclosure Date: December 15, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in autohtml.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the filename parameter, a different vector than CVE-2006-4190. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2007-5032
Disclosure Date: September 21, 2007 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in admin.php in Francisco Burzi PHP-Nuke allows remote attackers to add administrative accounts via an AddAuthor action with modified add_name and add_radminsuper parameters.
0
Attacker Value
Unknown
CVE-2007-4212
Disclosure Date: August 08, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Search Module in PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via a trailing "<" instead of a ">" in (1) the onerror attribute of an IMG element, (2) the onload attribute of an IFRAME element, or (3) redirect users to other sites via the META tag.
0
Attacker Value
Unknown
CVE-2007-1520
Disclosure Date: March 20, 2007 (last updated October 04, 2023)
The cross-site request forgery (CSRF) protection in PHP-Nuke 8.0 and earlier does not ensure the SERVER superglobal is an array before validating the HTTP_REFERER, which allows remote attackers to conduct CSRF attacks.
0
Attacker Value
Unknown
CVE-2007-1519
Disclosure Date: March 20, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke 8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search operation in the Downloads module, a different product than CVE-2006-3948.
0