Show filters
27 Total Results
Displaying 1-10 of 27
Sort by:
Attacker Value
Unknown

CVE-2020-24770

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
SQL injection vulnerability in modrules.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Attacker Value
Unknown

CVE-2020-24769

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the classes parameter.
Attacker Value
Unknown

CVE-2020-24771

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.
Attacker Value
Unknown

CVE-2017-15305

Disclosure Date: October 15, 2017 (last updated November 26, 2024)
XSS exists in NexusPHP 1.5 via the keyword parameter to messages.php.
0
Attacker Value
Unknown

CVE-2017-12792

Disclosure Date: October 03, 2017 (last updated November 26, 2024)
Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) linkname, (2) url, or (3) title parameter in an add action to linksmanage.php.
0
Attacker Value
Unknown

CVE-2017-14534

Disclosure Date: September 18, 2017 (last updated November 26, 2024)
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF.
0
Attacker Value
Unknown

CVE-2017-14512

Disclosure Date: September 17, 2017 (last updated November 26, 2024)
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different vulnerability than CVE-2017-12981.
0
Attacker Value
Unknown

CVE-2017-14347

Disclosure Date: September 12, 2017 (last updated November 26, 2024)
NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to fun.php in a delete action.
0
Attacker Value
Unknown

CVE-2017-12906

Disclosure Date: September 07, 2017 (last updated February 15, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in NexusPHP allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) cheaters.php or (2) confirm_resend.php.
0
Attacker Value
Unknown

CVE-2017-12838

Disclosure Date: September 07, 2017 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests that (1) send manas via a request to mybonus.php or (2) add administrators via unspecified vectors.
0