Show filters
124 Total Results
Displaying 51-60 of 124
Sort by:
Attacker Value
Unknown

CVE-2005-1024

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) my_headlines, (2) userinfo, or (3) search, which reveals the path in a PHP error message.
0
Attacker Value
Unknown

CVE-2005-0998

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The Web_Links module for PHP-Nuke 7.6 allows remote attackers to obtain sensitive information via an invalid show parameter, which triggers a division by zero PHP error that leaks the full pathname of the server.
0
Attacker Value
Unknown

CVE-2005-1180

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
HTTP Response Splitting vulnerability in the Surveys module in PHP-Nuke 7.6 allows remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the forwarder parameter.
0
Attacker Value
Unknown

CVE-2005-0997

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 7.6 allow remote attackers to execute arbitrary SQL commands via (1) the email or url parameters in the Add function, (2) the url parameter in the modifylinkrequestS function, (3) the orderby or min parameters in the viewlink function, (4) the orderby, min, or show parameters in the search function, or (5) the ratenum parameter in the MostPopular function.
0
Attacker Value
Unknown

CVE-2005-0999

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
SQL injection vulnerability in the Top module for PHP-Nuke 6.x through 7.6 allows remote attackers to execute arbitrary SQL commands via the querylang parameter.
0
Attacker Value
Unknown

CVE-2005-0434

Disclosure Date: February 15, 2005 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 7.5 allow remote attackers to inject arbitrary HTML or web script via (1) the newdownloadshowdays parameter in a NewDownloads operation or (2) the newlinkshowdays parameter in a NewLinks operation.
0
Attacker Value
Unknown

CVE-2005-0433

Disclosure Date: February 15, 2005 (last updated February 22, 2025)
Php-Nuke 7.5 allows remote attackers to determine the full path of the web server via invalid or missing arguments to (1) db.php, (2) mainfile.php, (3) Downloads/index.php, or (4) Web_Links/index.php, which lists the path in a PHP error message.
0
Attacker Value
Unknown

CVE-2004-1842

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a URL to admin.php.
Attacker Value
Unknown

CVE-2004-2020

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 6.x through 7.3 allow remote attackers to inject arbitrary HTML or web script into the (1) optionbox parameter in the News module, (2) date parameter in the Statistics module, (3) year, month, and month_1 parameters in the Stories_Archive module, (4) mode, order, and thold parameters in the Surveys module, or (5) a SQL statement to index.php, as processed by mainfile.php.
0
Attacker Value
Unknown

CVE-2004-1914

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL commands via the eid parameter.
0