Show filters
124 Total Results
Displaying 21-30 of 124
Sort by:
Attacker Value
Unknown
CVE-2007-1449
Disclosure Date: March 14, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.
0
Attacker Value
Unknown
CVE-2007-1450
Disclosure Date: March 14, 2007 (last updated October 04, 2023)
SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Top or News module via the lang parameter.
0
Attacker Value
Unknown
CVE-2007-1061
Disclosure Date: February 22, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" block is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header (HTTP_REFERER variable).
0
Attacker Value
Unknown
CVE-2007-0372
Disclosure Date: January 19, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 7.9 allow remote attackers to execute arbitrary SQL commands via (1) the active parameter in admin/modules/modules.php; the (2) ad_class, (3) imageurl, (4) clickurl, (5) ad_code, or (6) position parameter in modules/Advertising/admin/index.php; or unspecified vectors in the (7) advertising, (8) weblinks, or (9) reviews section.
0
Attacker Value
Unknown
CVE-2007-0309
Disclosure Date: January 18, 2007 (last updated October 04, 2023)
SQL injection vulnerability in blocks/block-Old_Articles.php in Francisco Burzi PHP-Nuke 7.9 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat parameter.
0
Attacker Value
Unknown
CVE-2006-6234
Disclosure Date: December 02, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the Content module in PHP-Nuke 6.0, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via (1) the cid parameter in a list_pages_categories action or (2) the pid parameter in a showpage action.
0
Attacker Value
Unknown
CVE-2006-6200
Disclosure Date: December 01, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the (1) rate_article and (2) rate_complete functions in modules/News/index.php in the News module in Francisco Burzi PHP-Nuke 7.9 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the sid parameter.
0
Attacker Value
Unknown
CVE-2006-5720
Disclosure Date: November 04, 2006 (last updated October 04, 2023)
SQL injection vulnerability in modules/journal/search.php in the Journal module in Francisco Burzi PHP-Nuke 7.9 and earlier allows remote attackers to execute arbitrary SQL commands via the forwhat parameter.
0
Attacker Value
Unknown
CVE-2006-5525
Disclosure Date: October 26, 2006 (last updated October 04, 2023)
Incomplete blacklist vulnerability in mainfile.php in PHP-Nuke 7.9 and earlier allows remote attackers to conduct SQL injection attacks via (1) "/**/UNION " or (2) " UNION/**/" sequences, which are not rejected by the protection mechanism, as demonstrated by a SQL injection via the eid parameter in a search action in the Encyclopedia module in modules.php.
0
Attacker Value
Unknown
CVE-2006-5494
Disclosure Date: October 25, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB module for PHP-Nuke allow remote attackers to execute arbitrary PHP code via a URL in the (1) adminpath or (2) basepath parameters. NOTE: this issue might overlap CVE-2006-6795.
0