Show filters
124 Total Results
Displaying 61-70 of 124
Sort by:
Attacker Value
Unknown
CVE-2004-2296
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The preview_review function in the Reviews module in PHP-Nuke 6.0 to 7.3, when running on Windows systems, allows remote attackers to obtain sensitive information via an invalid date parameter, which generates an error message.
0
Attacker Value
Unknown
CVE-2004-2354
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-site scripting (XSS) attacks when MySQL errors are triggered.
0
Attacker Value
Unknown
CVE-2004-2019
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The WebLinks module in Php-Nuke 6.x through 7.3 allows remote attackers to obtain sensitive information via an invalid show parameter, which displays the full path in a PHP error message.
0
Attacker Value
Unknown
CVE-2004-1528
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The Event Calendar module 2.13 for PHP-Nuke allows remote attackers to gain sensitive information via an HTTP request to (1) config.php, (2) index.php, or (3) submit.php, which reveal the full path in an error message.
0
Attacker Value
Unknown
CVE-2004-2018
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
PHP remote file inclusion vulnerability in index.php in Php-Nuke 6.x through 7.3 allows remote attackers to execute arbitrary PHP code by modifying the modpath parameter to reference a URL on a remote web server that contains the code.
0
Attacker Value
Unknown
CVE-2004-1913
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject arbitrary web script or HTML via the eid parameter.
0
Attacker Value
Unknown
CVE-2004-1912
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke, allow remote attackers to obtain sensitive information via a URL with an invalid argument, which reveals the full path in an error message.
0
Attacker Value
Unknown
CVE-2004-2297
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The Reviews module in PHP-Nuke 6.0 to 7.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a large, out-of-range score parameter.
0
Attacker Value
Unknown
CVE-2004-1529
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary web script via the (1) type, (2) day, (3) month, or (4) year parameters in a Preview operation, or (5) event comments.
0
Attacker Value
Unknown
CVE-2004-2294
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Canonicalize-before-filter error in the send_review function in the Reviews module for PHP-Nuke 6.0 to 7.3 allows remote attackers to inject arbitrary web script or HTML via hex-encoded XSS sequences in the text parameter, which is checked for dangerous sequences before it is canonicalized, leading to a cross-site scripting (XSS) vulnerability.
0