Show filters
37 Total Results
Displaying 31-37 of 37
Sort by:
Attacker Value
Unknown

CVE-2004-1930

Disclosure Date: April 12, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie.
0
Attacker Value
Unknown

CVE-2004-1830

Disclosure Date: March 18, 2004 (last updated February 22, 2025)
error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (3) lang parameter, which leaks the pathname in a PHP error message.
0
Attacker Value
Unknown

CVE-2003-1435

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module.
0
Attacker Value
Unknown

CVE-2003-1468

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
The Web_Links module in PHP-Nuke 6.0 through 6.5 final allows remote attackers to obtain the full web server path via an invalid cid parameter that is non-numeric or null, which leaks the pathname in an error message.
0
Attacker Value
Unknown

CVE-2003-1400

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web script or HTML via the user_avatar parameter.
0
Attacker Value
Unknown

CVE-2003-0279

Disclosure Date: June 16, 2003 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php.
0
Attacker Value
Unknown

CVE-2002-1803

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in PHP-Nuke 6.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.
0