php-nuke records
24 published records for vendor php-nuke.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 15
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')11
- CWE-189 Numeric Errors1
- CWE-20 Improper Input Validation1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
24 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2007-1626Proof of concept | PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP codphp-nuke · iframe module | Critical9.3 | — | 3.1% | Mar 23, 2007 |
37Monitor | CVE-2008-4767Proof of concept | Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploadinphp-nuke · downloadsplus module · CWE-20 | Critical9.0 | — | 4.2% | Oct 28, 2008 |
30Monitor | CVE-2007-1034Proof of concept | SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attackerphp-nuke · emporium module · CWE-89 | High7.5 | — | 1.6% | Feb 21, 2007 |
30Monitor | CVE-2006-3598No exploit | SQL injection vulnerability in the Sections module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid paraphp-nuke · sections module | High7.5 | — | 1.4% | Jul 18, 2006 |
30Monitor | CVE-2006-6217No exploit | PHP remote file inclusion vulnerability in formdisp.php in the Mermaid 1.2 module for PHP-Nuke allows remote attackers to execute arbitrary php-nuke · mermaid module | High7.5 | — | 1.3% | Nov 30, 2006 |
30Monitor | CVE-2008-1298Proof of concept | SQL injection vulnerability in Hadith module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cat parameter inphp-nuke · hadith module · CWE-89 | High7.5 | — | 1.2% | Mar 12, 2008 |
30Monitor | CVE-2008-6865No exploit | SQL injection vulnerability in modules.php in the Sectionsnew module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands php-nuke · sections module · CWE-89 | High7.5 | — | 1.1% | Jul 14, 2009 |
30Monitor | CVE-2008-6866No exploit | SQL injection vulnerability in modules.php in the Current_Issue module for PHP-Nuke allows remote attackers to execute arbitrary SQL commandphp-nuke · current issue module · CWE-89 | High7.5 | — | 1.1% | Jul 14, 2009 |
30Monitor | CVE-2006-3599No exploit | SQL injection vulnerability in the Nuke Advanced Classifieds module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands vphp-nuke · advanced classified module | High7.5 | — | 1.1% | Jul 18, 2006 |
30Monitor | CVE-2008-1315Proof of concept | SQL injection vulnerability in the ZClassifieds module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cat paphp-nuke · zclassifieds · CWE-89 | High7.5 | — | 1.0% | Mar 13, 2008 |
30Monitor | CVE-2008-7226Proof of concept | SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers tophp-nuke · recipe module · CWE-89 | High7.5 | — | 1.0% | Sep 14, 2009 |
30Monitor | CVE-2008-0906Proof of concept | SQL injection vulnerability in the Docum module in PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parametephp-nuke · php-nuke module docum · CWE-89 | High7.5 | — | 1.0% | Feb 22, 2008 |
30Monitor | CVE-2008-0907Proof of concept | SQL injection vulnerability in the Inhalt module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parametephp-nuke · inhalt module · CWE-89 | High7.5 | — | 1.0% | Feb 22, 2008 |
30Monitor | CVE-2008-0934Proof of concept | SQL injection vulnerability in modules.php in the NukeC 2.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands vinukec · nukec · CWE-89 | High7.5 | — | 0.9% | Feb 25, 2008 |
30Monitor | CVE-2008-0922Proof of concept | SQL injection vulnerability in the Manuales 0.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid paphp-nuke · manuales · CWE-89 | High7.5 | — | 0.9% | Feb 22, 2008 |
28Monitor | CVE-2007-1934Proof of concept | Directory traversal vulnerability in member.php in the eBoard 1.0.7 module for PHP-Nuke allows remote attackers to include and execute arbitphp-nuke · eboard module | Medium6.8 | — | 2.5% | Apr 10, 2007 |
26Monitor | CVE-2006-2828Proof of concept | Global variable overwrite vulnerability in PHP-Nuke allows remote attackers to conduct remote PHP file inclusion attacks via a modified phpbphp-nuke · ev | Medium6.4 | — | 2.5% | Jun 5, 2006 |
21Monitor | CVE-2007-3332Proof of concept | Directory traversal vulnerability in Satellite.php in Satel Lite for PhpNuke allows remote attackers to read arbitrary files via a ..php-nuke · satel lite | Medium5.0 | — | 2.7% | Jun 21, 2007 |
21Monitor | CVE-2006-0185Proof of concept | Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary webphp-nuke · news module | Medium5.0 | — | 2.3% | Jan 12, 2006 |
21Monitor | CVE-2008-3573Proof of concept | The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the ts_randomphp-nuke · php-nuke · CWE-189 | Medium5.0 | — | 2.0% | Aug 10, 2008 |
18Monitor | CVE-2006-3948Proof of concept | Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke INP allows remote attackers to inject arbitrary web script or HTML via tphp-nuke · inp | Medium4.3 | — | 1.7% | Aug 1, 2006 |
18Monitor | CVE-2009-0302Proof of concept | SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arbphp-nuke · downloads module · CWE-89 | Medium4.6 | — | 1.5% | Jan 27, 2009 |
17Monitor | CVE-2008-5039Proof of concept | Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inject arbitrary web scphp-nuke · league module · CWE-79 | Medium4.3 | — | 1.5% | Nov 12, 2008 |
8Monitor | CVE-2006-4190Proof of concept | Directory traversal vulnerability in autohtml.php in the AutoHTML module for PHP-Nuke allows local users to include arbitrary files via a ..php-nuke · autohtml module | Low2.1 | — | 0.8% | Aug 16, 2006 |
- CVE-2007-162638Monitor
PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP cod
CriticalCVSS 9.3Proof of conceptEPSS 3%php-nuke · iframe moduleMar 23, 2007
- CVE-2008-476737Monitor
Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploadin
CriticalCVSS 9.0Proof of conceptEPSS 4%php-nuke · downloadsplus moduleOct 28, 2008
- CVE-2007-103430Monitor
SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attacker
HighCVSS 7.5Proof of conceptEPSS 2%php-nuke · emporium moduleFeb 21, 2007
- CVE-2006-359830Monitor
SQL injection vulnerability in the Sections module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid para
HighCVSS 7.5No exploitEPSS 1%php-nuke · sections moduleJul 18, 2006
- CVE-2006-621730Monitor
PHP remote file inclusion vulnerability in formdisp.php in the Mermaid 1.2 module for PHP-Nuke allows remote attackers to execute arbitrary
HighCVSS 7.5No exploitEPSS 1%php-nuke · mermaid moduleNov 30, 2006
- CVE-2008-129830Monitor
SQL injection vulnerability in Hadith module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cat parameter in
HighCVSS 7.5Proof of conceptEPSS 1%php-nuke · hadith moduleMar 12, 2008
- CVE-2008-686530Monitor
SQL injection vulnerability in modules.php in the Sectionsnew module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands
HighCVSS 7.5No exploitEPSS 1%php-nuke · sections moduleJul 14, 2009
- CVE-2008-686630Monitor
SQL injection vulnerability in modules.php in the Current_Issue module for PHP-Nuke allows remote attackers to execute arbitrary SQL command
HighCVSS 7.5No exploitEPSS 1%php-nuke · current issue moduleJul 14, 2009
- CVE-2006-359930Monitor
SQL injection vulnerability in the Nuke Advanced Classifieds module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands v
HighCVSS 7.5No exploitEPSS 1%php-nuke · advanced classified moduleJul 18, 2006
- CVE-2008-131530Monitor
SQL injection vulnerability in the ZClassifieds module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cat pa
HighCVSS 7.5Proof of conceptEPSS 1%php-nuke · zclassifiedsMar 13, 2008
- CVE-2008-722630Monitor
SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers to
HighCVSS 7.5Proof of conceptEPSS 1%php-nuke · recipe moduleSep 14, 2009
- CVE-2008-090630Monitor
SQL injection vulnerability in the Docum module in PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid paramete
HighCVSS 7.5Proof of conceptEPSS 1%php-nuke · php-nuke module documFeb 22, 2008
- CVE-2008-090730Monitor
SQL injection vulnerability in the Inhalt module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid paramete
HighCVSS 7.5Proof of conceptEPSS 1%php-nuke · inhalt moduleFeb 22, 2008
- CVE-2008-093430Monitor
SQL injection vulnerability in modules.php in the NukeC 2.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands vi
HighCVSS 7.5Proof of conceptEPSS 1%nukec · nukecFeb 25, 2008
- CVE-2008-092230Monitor
SQL injection vulnerability in the Manuales 0.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid pa
HighCVSS 7.5Proof of conceptEPSS 1%php-nuke · manualesFeb 22, 2008
- CVE-2007-193428Monitor
Directory traversal vulnerability in member.php in the eBoard 1.0.7 module for PHP-Nuke allows remote attackers to include and execute arbit
MediumCVSS 6.8Proof of conceptEPSS 2%php-nuke · eboard moduleApr 10, 2007
- CVE-2006-282826Monitor
Global variable overwrite vulnerability in PHP-Nuke allows remote attackers to conduct remote PHP file inclusion attacks via a modified phpb
MediumCVSS 6.4Proof of conceptEPSS 3%php-nuke · evJun 5, 2006
- CVE-2007-333221Monitor
Directory traversal vulnerability in Satellite.php in Satel Lite for PhpNuke allows remote attackers to read arbitrary files via a ..
MediumCVSS 5.0Proof of conceptEPSS 3%php-nuke · satel liteJun 21, 2007
- CVE-2006-018521Monitor
Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary web
MediumCVSS 5.0Proof of conceptEPSS 2%php-nuke · news moduleJan 12, 2006
- CVE-2008-357321Monitor
The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the ts_random
MediumCVSS 5.0Proof of conceptEPSS 2%php-nuke · php-nukeAug 10, 2008
- CVE-2006-394818Monitor
Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke INP allows remote attackers to inject arbitrary web script or HTML via t
MediumCVSS 4.3Proof of conceptEPSS 2%php-nuke · inpAug 1, 2006
- CVE-2009-030218Monitor
SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arb
MediumCVSS 4.6Proof of conceptEPSS 1%php-nuke · downloads moduleJan 27, 2009
- CVE-2008-503917Monitor
Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inject arbitrary web sc
MediumCVSS 4.3Proof of conceptEPSS 1%php-nuke · league moduleNov 12, 2008
- CVE-2006-41908Monitor
Directory traversal vulnerability in autohtml.php in the AutoHTML module for PHP-Nuke allows local users to include arbitrary files via a ..
LowCVSS 2.1Proof of conceptEPSS 1%php-nuke · autohtml moduleAug 16, 2006