Show filters
37 Total Results
Displaying 31-37 of 37
Sort by:
Attacker Value
Unknown
CVE-2004-1930
Disclosure Date: April 12, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie.
0
Attacker Value
Unknown
CVE-2004-1830
Disclosure Date: March 18, 2004 (last updated February 22, 2025)
error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (3) lang parameter, which leaks the pathname in a PHP error message.
0
Attacker Value
Unknown
CVE-2003-1435
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module.
0
Attacker Value
Unknown
CVE-2003-1468
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
The Web_Links module in PHP-Nuke 6.0 through 6.5 final allows remote attackers to obtain the full web server path via an invalid cid parameter that is non-numeric or null, which leaks the pathname in an error message.
0
Attacker Value
Unknown
CVE-2003-1400
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web script or HTML via the user_avatar parameter.
0
Attacker Value
Unknown
CVE-2003-0279
Disclosure Date: June 16, 2003 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php.
0
Attacker Value
Unknown
CVE-2002-1803
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in PHP-Nuke 6.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.
0