phpnuke records
40 published records for vendor phpnuke.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 23
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')22
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
40 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-30177No exploit | There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execution.phpnuke · php-nuke · CWE-89 | Critical9.8 | — | 2.4% | Apr 7, 2021 |
37Monitor | CVE-2008-4767Proof of concept | Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploadinphp-nuke · downloadsplus module · CWE-20 | Critical9.0 | — | 4.2% | Oct 28, 2008 |
36Monitor | CVE-2004-1842Proof of concept | Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via phpnuke · php-nuke · CWE-352 | High8.8 | — | 1.7% | Dec 31, 2004 |
33Monitor | CVE-2001-0899Proof of concept | Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variablephpnuke · php-nuke | High7.5 | — | 8.9% | Nov 16, 2001 |
31Monitor | CVE-2006-5494Proof of concept | Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB module for PHP-Nuke allophpnuke · php-nuke · CWE-94 | High7.5 | — | 3.2% | Oct 25, 2006 |
31Monitor | CVE-2014-3934Proof of concept | SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL commands via the topphpnuke · php-nuke · CWE-89 | High7.5 | — | 2.2% | Jun 2, 2014 |
31Monitor | CVE-2008-2020No exploit | The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) my123tkshop · e-commerce-suite · CWE-330 | High7.5 | — | 1.7% | Apr 29, 2008 |
30Monitor | CVE-2008-1219Proof of concept | SQL injection vulnerability in the Kutub-i Sitte (KutubiSitte) 1.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commphpnuke · kutubisitte component · CWE-89 | High7.5 | — | 1.2% | Mar 10, 2008 |
30Monitor | CVE-2008-7038Proof of concept | SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid parphpnuke · php-nuke · CWE-89 | High7.5 | — | 1.2% | Aug 24, 2009 |
30Monitor | CVE-2011-1480No exploit | SQL injection vulnerability in admin.php in the administration backend in Francisco Burzi PHP-Nuke 8.0 and earlier allows remote attackers tphpnuke · php-nuke · CWE-89 | High7.5 | — | 1.2% | Jun 20, 2011 |
30Monitor | CVE-2008-0879Proof of concept | SQL injection vulnerability in modules.php in the Web_Links module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands viphpnuke · web links module · CWE-89 | High7.5 | — | 1.1% | Feb 21, 2008 |
30Monitor | CVE-2008-6865No exploit | SQL injection vulnerability in modules.php in the Sectionsnew module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands php-nuke · sections module · CWE-89 | High7.5 | — | 1.1% | Jul 14, 2009 |
30Monitor | CVE-2008-4804No exploit | SQL injection vulnerability in the Gallery module 1.3 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the aid parnukedgallery · gallery · CWE-89 | High7.5 | — | 1.1% | Oct 31, 2008 |
30Monitor | CVE-2008-6728No exploit | SQL injection vulnerability in the Sections module in PHP-Nuke, probably before 8.0, allows remote attackers to execute arbitrary SQL commanphpnuke · php-nuke · CWE-89 | High7.5 | — | 1.1% | Apr 20, 2009 |
30Monitor | CVE-2008-0880Proof of concept | SQL injection vulnerability in modules.php in the EasyContent module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands phpnuke · easycontent module · CWE-89 | High7.5 | — | 1.1% | Feb 21, 2008 |
30Monitor | CVE-2008-0881Proof of concept | SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands viaphpnuke · okul module · CWE-89 | High7.5 | — | 1.1% | Feb 21, 2008 |
30Monitor | CVE-2010-5083Proof of concept | SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url pphpnuke · php-nuke · CWE-89 | High7.5 | — | 1.0% | Feb 14, 2012 |
30Monitor | CVE-2007-1450No exploit | SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Topphpnuke · php-nuke | High7.5 | — | 1.0% | Mar 14, 2007 |
30Monitor | CVE-2008-3151Proof of concept | SQL injection vulnerability in the 4ndvddb 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parphpnuke · 4ndvddb · CWE-89 | High7.5 | — | 1.0% | Jul 11, 2008 |
30Monitor | CVE-2008-0827Proof of concept | SQL injection vulnerability in the Books module of PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.phpnuke · book · CWE-89 | High7.5 | — | 1.0% | Feb 19, 2008 |
30Monitor | CVE-2008-1314Proof of concept | SQL injection vulnerability in the Johannes Hass gaestebuch 2.2 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commandjohannes hass · gaestebuch module · CWE-89 | High7.5 | — | 1.0% | Mar 12, 2008 |
30Monitor | CVE-2008-7226Proof of concept | SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers tophp-nuke · recipe module · CWE-89 | High7.5 | — | 1.0% | Sep 14, 2009 |
30Monitor | CVE-2008-1053Proof of concept | Multiple SQL injection vulnerabilities in the Kose_Yazilari module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands viaphpnuke · kose yazilari module · CWE-89 | High7.5 | — | 1.0% | Feb 27, 2008 |
30Monitor | CVE-2008-6779Proof of concept | SQL injection vulnerability in the Sarkilar module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parametphpnuke · php-nuke · CWE-89 | High7.5 | — | 1.0% | May 1, 2009 |
30Monitor | CVE-2009-1842Proof of concept | SQL injection vulnerability in main/tracking/userLog.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL cophpnuke · php-nuke · CWE-89 | High7.5 | — | 1.0% | Jun 1, 2009 |
- CVE-2021-3017740Plan
There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execution.
CriticalCVSS 9.8No exploitEPSS 2%phpnuke · php-nukeApr 7, 2021
- CVE-2008-476737Monitor
Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploadin
CriticalCVSS 9.0Proof of conceptEPSS 4%php-nuke · downloadsplus moduleOct 28, 2008
- CVE-2004-184236Monitor
Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via
HighCVSS 8.8Proof of conceptEPSS 2%phpnuke · php-nukeDec 31, 2004
- CVE-2001-089933Monitor
Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variable
HighCVSS 7.5Proof of conceptEPSS 9%phpnuke · php-nukeNov 16, 2001
- CVE-2006-549431Monitor
Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB module for PHP-Nuke allo
HighCVSS 7.5Proof of conceptEPSS 3%phpnuke · php-nukeOct 25, 2006
- CVE-2014-393431Monitor
SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL commands via the top
HighCVSS 7.5Proof of conceptEPSS 2%phpnuke · php-nukeJun 2, 2014
- CVE-2008-202031Monitor
The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3)
HighCVSS 7.5No exploitEPSS 2%my123tkshop · e-commerce-suiteApr 29, 2008
- CVE-2008-121930Monitor
SQL injection vulnerability in the Kutub-i Sitte (KutubiSitte) 1.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL comm
HighCVSS 7.5Proof of conceptEPSS 1%phpnuke · kutubisitte componentMar 10, 2008
- CVE-2008-703830Monitor
SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid par
HighCVSS 7.5Proof of conceptEPSS 1%phpnuke · php-nukeAug 24, 2009
- CVE-2011-148030Monitor
SQL injection vulnerability in admin.php in the administration backend in Francisco Burzi PHP-Nuke 8.0 and earlier allows remote attackers t
HighCVSS 7.5No exploitEPSS 1%phpnuke · php-nukeJun 20, 2011
- CVE-2008-087930Monitor
SQL injection vulnerability in modules.php in the Web_Links module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands vi
HighCVSS 7.5Proof of conceptEPSS 1%phpnuke · web links moduleFeb 21, 2008
- CVE-2008-686530Monitor
SQL injection vulnerability in modules.php in the Sectionsnew module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands
HighCVSS 7.5No exploitEPSS 1%php-nuke · sections moduleJul 14, 2009
- CVE-2008-480430Monitor
SQL injection vulnerability in the Gallery module 1.3 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the aid par
HighCVSS 7.5No exploitEPSS 1%nukedgallery · galleryOct 31, 2008
- CVE-2008-672830Monitor
SQL injection vulnerability in the Sections module in PHP-Nuke, probably before 8.0, allows remote attackers to execute arbitrary SQL comman
HighCVSS 7.5No exploitEPSS 1%phpnuke · php-nukeApr 20, 2009
- CVE-2008-088030Monitor
SQL injection vulnerability in modules.php in the EasyContent module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands
HighCVSS 7.5Proof of conceptEPSS 1%phpnuke · easycontent moduleFeb 21, 2008
- CVE-2008-088130Monitor
SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 1%phpnuke · okul moduleFeb 21, 2008
- CVE-2010-508330Monitor
SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url p
HighCVSS 7.5Proof of conceptEPSS 1%phpnuke · php-nukeFeb 14, 2012
- CVE-2007-145030Monitor
SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Top
HighCVSS 7.5No exploitEPSS 1%phpnuke · php-nukeMar 14, 2007
- CVE-2008-315130Monitor
SQL injection vulnerability in the 4ndvddb 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id par
HighCVSS 7.5Proof of conceptEPSS 1%phpnuke · 4ndvddbJul 11, 2008
- CVE-2008-082730Monitor
SQL injection vulnerability in the Books module of PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.
HighCVSS 7.5Proof of conceptEPSS 1%phpnuke · bookFeb 19, 2008
- CVE-2008-131430Monitor
SQL injection vulnerability in the Johannes Hass gaestebuch 2.2 module for PHP-Nuke allows remote attackers to execute arbitrary SQL command
HighCVSS 7.5Proof of conceptEPSS 1%johannes hass · gaestebuch moduleMar 12, 2008
- CVE-2008-722630Monitor
SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers to
HighCVSS 7.5Proof of conceptEPSS 1%php-nuke · recipe moduleSep 14, 2009
- CVE-2008-105330Monitor
Multiple SQL injection vulnerabilities in the Kose_Yazilari module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 1%phpnuke · kose yazilari moduleFeb 27, 2008
- CVE-2008-677930Monitor
SQL injection vulnerability in the Sarkilar module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id paramet
HighCVSS 7.5Proof of conceptEPSS 1%phpnuke · php-nukeMay 1, 2009
- CVE-2009-184230Monitor
SQL injection vulnerability in main/tracking/userLog.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL co
HighCVSS 7.5Proof of conceptEPSS 1%phpnuke · php-nukeJun 1, 2009