Show filters
31 Total Results
Displaying 1-10 of 31
Sort by:
Attacker Value
Unknown

CVE-2022-46890

Disclosure Date: January 19, 2023 (last updated October 08, 2023)
Weak access control in NexusPHP before 1.7.33 allows a remote authenticated user to edit any post in the forum (this is caused by a lack of checks performed by the /forums.php?action=post page).
Attacker Value
Unknown

CVE-2022-46889

Disclosure Date: January 19, 2023 (last updated October 08, 2023)
A persistent cross-site scripting (XSS) vulnerability in NexusPHP before 1.7.33 allows remote authenticated attackers to permanently inject arbitrary web script or HTML via the title parameter used in /subtitles.php.
Attacker Value
Unknown

CVE-2022-46888

Disclosure Date: January 19, 2023 (last updated October 08, 2023)
Multiple reflective cross-site scripting (XSS) vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to inject arbitrary web script or HTML via the secret parameter in /login.php; q parameter in /user-ban-log.php; query parameter in /log.php; text parameter in /moresmiles.php; q parameter in myhr.php; or id parameter in /viewrequests.php.
Attacker Value
Unknown

CVE-2022-46887

Disclosure Date: January 19, 2023 (last updated October 08, 2023)
Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takeconfirm.php; the delcheater parameter in cheaterbox.php; or the usernw parameter in nowarn.php.
Attacker Value
Unknown

CVE-2020-24770

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
SQL injection vulnerability in modrules.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Attacker Value
Unknown

CVE-2020-24769

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the classes parameter.
Attacker Value
Unknown

CVE-2020-24771

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.
Attacker Value
Unknown

CVE-2017-15305

Disclosure Date: October 15, 2017 (last updated November 26, 2024)
XSS exists in NexusPHP 1.5 via the keyword parameter to messages.php.
0
Attacker Value
Unknown

CVE-2017-12792

Disclosure Date: October 03, 2017 (last updated November 26, 2024)
Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) linkname, (2) url, or (3) title parameter in an add action to linksmanage.php.
0
Attacker Value
Unknown

CVE-2017-14534

Disclosure Date: September 18, 2017 (last updated November 26, 2024)
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF.
0