Show filters
97 Total Results
Displaying 71-80 of 97
Sort by:
Attacker Value
Unknown

CVE-2004-1817

Disclosure Date: March 15, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in modules.php in Php-Nuke 7.1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) Your Name field, (2) e-mail field, (3) nicname field, (4) fname parameter, (5) ratenum parameter, or (6) search field.
0
Attacker Value
Unknown

CVE-2003-1547

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in block-Forums.php in the Splatt Forum module for PHP-Nuke 6.x allows remote attackers to inject arbitrary web script or HTML via the subject parameter.
0
Attacker Value
Unknown

CVE-2003-1210

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to the getit function or the (2) min parameter to the search function.
0
Attacker Value
Unknown

CVE-2003-1526

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
PHP-Nuke 7.0 allows remote attackers to obtain the installation path via certain characters such as (1) ", (2) ', or (3) > in the search field, which reveals the path in an error message.
0
Attacker Value
Unknown

CVE-2003-1435

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module.
0
Attacker Value
Unknown

CVE-2003-1468

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
The Web_Links module in PHP-Nuke 6.0 through 6.5 final allows remote attackers to obtain the full web server path via an invalid cid parameter that is non-numeric or null, which leaks the pathname in an error message.
0
Attacker Value
Unknown

CVE-2003-1400

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web script or HTML via the user_avatar parameter.
0
Attacker Value
Unknown

CVE-2003-0279

Disclosure Date: June 16, 2003 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 5.x through 6.5 allows remote attackers to steal sensitive information via numeric fields, as demonstrated using (1) the viewlink function and cid parameter, or (2) index.php.
0
Attacker Value
Unknown

CVE-2003-0318

Disclosure Date: June 09, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the Statistics module for PHP-Nuke 6.0 and earlier allows remote attackers to insert arbitrary web script via the year parameter.
0
Attacker Value
Unknown

CVE-2002-1803

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in PHP-Nuke 6.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.
0