Show filters
97 Total Results
Displaying 51-60 of 97
Sort by:
Attacker Value
Unknown

CVE-2004-0732

Disclosure Date: July 27, 2004 (last updated February 22, 2025)
SQL injection vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to execute arbitrary SQL statements via the instory parameter.
0
Attacker Value
Unknown

CVE-2004-0738

Disclosure Date: July 27, 2004 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in the Search module in Php-Nuke allow remote attackers to execute arbitrary SQL via the (1) min or (2) categ parameters.
0
Attacker Value
Unknown

CVE-2004-0737

Disclosure Date: July 27, 2004 (last updated February 22, 2025)
Multiple cross-site scripting vulnerabilities in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) max, (3) sel1, (4) sel2, (5) sel3, (6) sel4, (7) sel5, (8) match, (9) mod1, (10) mod2, or (11) mod3 parameters.
0
Attacker Value
Unknown

CVE-2004-0736

Disclosure Date: July 27, 2004 (last updated February 22, 2025)
The search module in Php-Nuke allows remote attackers to gain sensitive information via the (1) "**" or (2) "+" search patterns, which reveals the path in an error message.
0
Attacker Value
Unknown

CVE-2004-2044

Disclosure Date: June 01, 2004 (last updated February 22, 2025)
PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER['PHP_SELF'] to identify the calling script, which allows remote attackers to directly access scripts, obtain path information via a PHP error message, and possibly gain access, as demonstrated using an HTTP request that contains the "admin.php" string.
0
Attacker Value
Unknown

CVE-2004-1999

Disclosure Date: May 05, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to inject arbitrary HTML and web script via the (1) ttitle or (2) sid parameters to modules.php.
0
Attacker Value
Unknown

CVE-2004-1998

Disclosure Date: May 05, 2004 (last updated February 22, 2025)
The Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to gain sensitive information via an invalid show parameter to modules.php, which reveals the full path in a PHP error message.
0
Attacker Value
Unknown

CVE-2004-1984

Disclosure Date: May 02, 2004 (last updated February 22, 2025)
Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) phpinfo.php, (2) addpic.php, (3) config.php, (4) db_input.php, (5) displayecard.php, (6) ecard.php, (7) crop.inc.php, which reveal the full path in a PHP error message.
0
Attacker Value
Unknown

CVE-2004-1987

Disclosure Date: April 30, 2004 (last updated February 22, 2025)
picmgmtbatch.inc.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to execute arbitrary commands via shell metacharacters in the (1) $CONFIG['impath'] or (2) $CONFIG['jpeg_qual'] parameters.
0
Attacker Value
Unknown

CVE-2004-1985

Disclosure Date: April 30, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web script via the CPG_URL parameter.
0