Skip to content
Noroxi

phpnuke records

40 published records for vendor phpnuke.

All records

40 records
  • There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execution.

    CriticalCVSS 9.8No exploitEPSS 2%

    phpnuke · php-nukeApr 7, 2021

  • CVE-2008-4767
    37Monitor

    Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploadin

    CriticalCVSS 9.0Proof of conceptEPSS 4%

    php-nuke · downloadsplus moduleOct 28, 2008

  • CVE-2004-1842
    36Monitor

    Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via

    HighCVSS 8.8Proof of conceptEPSS 2%

    phpnuke · php-nukeDec 31, 2004

  • CVE-2001-0899
    33Monitor

    Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variable

    HighCVSS 7.5Proof of conceptEPSS 9%

    phpnuke · php-nukeNov 16, 2001

  • CVE-2006-5494
    31Monitor

    Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB module for PHP-Nuke allo

    HighCVSS 7.5Proof of conceptEPSS 3%

    phpnuke · php-nukeOct 25, 2006

  • CVE-2014-3934
    31Monitor

    SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL commands via the top

    HighCVSS 7.5Proof of conceptEPSS 2%

    phpnuke · php-nukeJun 2, 2014

  • CVE-2008-2020
    31Monitor

    The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3)

    HighCVSS 7.5No exploitEPSS 2%

    my123tkshop · e-commerce-suiteApr 29, 2008

  • CVE-2008-1219
    30Monitor

    SQL injection vulnerability in the Kutub-i Sitte (KutubiSitte) 1.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL comm

    HighCVSS 7.5Proof of conceptEPSS 1%

    phpnuke · kutubisitte componentMar 10, 2008

  • CVE-2008-7038
    30Monitor

    SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid par

    HighCVSS 7.5Proof of conceptEPSS 1%

    phpnuke · php-nukeAug 24, 2009

  • CVE-2011-1480
    30Monitor

    SQL injection vulnerability in admin.php in the administration backend in Francisco Burzi PHP-Nuke 8.0 and earlier allows remote attackers t

    HighCVSS 7.5No exploitEPSS 1%

    phpnuke · php-nukeJun 20, 2011

  • CVE-2008-0879
    30Monitor

    SQL injection vulnerability in modules.php in the Web_Links module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands vi

    HighCVSS 7.5Proof of conceptEPSS 1%

    phpnuke · web links moduleFeb 21, 2008

  • CVE-2008-6865
    30Monitor

    SQL injection vulnerability in modules.php in the Sectionsnew module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands

    HighCVSS 7.5No exploitEPSS 1%

    php-nuke · sections moduleJul 14, 2009

  • CVE-2008-4804
    30Monitor

    SQL injection vulnerability in the Gallery module 1.3 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the aid par

    HighCVSS 7.5No exploitEPSS 1%

    nukedgallery · galleryOct 31, 2008

  • CVE-2008-6728
    30Monitor

    SQL injection vulnerability in the Sections module in PHP-Nuke, probably before 8.0, allows remote attackers to execute arbitrary SQL comman

    HighCVSS 7.5No exploitEPSS 1%

    phpnuke · php-nukeApr 20, 2009

  • CVE-2008-0880
    30Monitor

    SQL injection vulnerability in modules.php in the EasyContent module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands

    HighCVSS 7.5Proof of conceptEPSS 1%

    phpnuke · easycontent moduleFeb 21, 2008

  • CVE-2008-0881
    30Monitor

    SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via

    HighCVSS 7.5Proof of conceptEPSS 1%

    phpnuke · okul moduleFeb 21, 2008

  • CVE-2010-5083
    30Monitor

    SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url p

    HighCVSS 7.5Proof of conceptEPSS 1%

    phpnuke · php-nukeFeb 14, 2012

  • CVE-2007-1450
    30Monitor

    SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Top

    HighCVSS 7.5No exploitEPSS 1%

    phpnuke · php-nukeMar 14, 2007

  • CVE-2008-3151
    30Monitor

    SQL injection vulnerability in the 4ndvddb 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id par

    HighCVSS 7.5Proof of conceptEPSS 1%

    phpnuke · 4ndvddbJul 11, 2008

  • CVE-2008-0827
    30Monitor

    SQL injection vulnerability in the Books module of PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    HighCVSS 7.5Proof of conceptEPSS 1%

    phpnuke · bookFeb 19, 2008

  • CVE-2008-1314
    30Monitor

    SQL injection vulnerability in the Johannes Hass gaestebuch 2.2 module for PHP-Nuke allows remote attackers to execute arbitrary SQL command

    HighCVSS 7.5Proof of conceptEPSS 1%

    johannes hass · gaestebuch moduleMar 12, 2008

  • CVE-2008-7226
    30Monitor

    SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers to

    HighCVSS 7.5Proof of conceptEPSS 1%

    php-nuke · recipe moduleSep 14, 2009

  • CVE-2008-1053
    30Monitor

    Multiple SQL injection vulnerabilities in the Kose_Yazilari module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via

    HighCVSS 7.5Proof of conceptEPSS 1%

    phpnuke · kose yazilari moduleFeb 27, 2008

  • CVE-2008-6779
    30Monitor

    SQL injection vulnerability in the Sarkilar module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id paramet

    HighCVSS 7.5Proof of conceptEPSS 1%

    phpnuke · php-nukeMay 1, 2009

  • CVE-2009-1842
    30Monitor

    SQL injection vulnerability in main/tracking/userLog.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL co

    HighCVSS 7.5Proof of conceptEPSS 1%

    phpnuke · php-nukeJun 1, 2009