Записи php-nuke
24 опубликованных записей вендора php-nuke.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 15
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')11
- CWE-189 Numeric Errors1
- CWE-20 Improper Input Validation1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
24 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
38Наблюдать | CVE-2007-1626Proof of concept | PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP codphp-nuke · iframe module | Критическая9,3 | — | 3,1 % | 23 мар. 2007 г. |
37Наблюдать | CVE-2008-4767Proof of concept | Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploadinphp-nuke · downloadsplus module · CWE-20 | Критическая9,0 | — | 4,2 % | 28 окт. 2008 г. |
30Наблюдать | CVE-2007-1034Proof of concept | SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attackerphp-nuke · emporium module · CWE-89 | Высокая7,5 | — | 1,6 % | 21 февр. 2007 г. |
30Наблюдать | CVE-2006-3598Эксплойта нет | SQL injection vulnerability in the Sections module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid paraphp-nuke · sections module | Высокая7,5 | — | 1,4 % | 18 июл. 2006 г. |
30Наблюдать | CVE-2006-6217Эксплойта нет | PHP remote file inclusion vulnerability in formdisp.php in the Mermaid 1.2 module for PHP-Nuke allows remote attackers to execute arbitrary php-nuke · mermaid module | Высокая7,5 | — | 1,3 % | 30 нояб. 2006 г. |
30Наблюдать | CVE-2008-1298Proof of concept | SQL injection vulnerability in Hadith module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cat parameter inphp-nuke · hadith module · CWE-89 | Высокая7,5 | — | 1,2 % | 12 мар. 2008 г. |
30Наблюдать | CVE-2008-6865Эксплойта нет | SQL injection vulnerability in modules.php in the Sectionsnew module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands php-nuke · sections module · CWE-89 | Высокая7,5 | — | 1,1 % | 14 июл. 2009 г. |
30Наблюдать | CVE-2008-6866Эксплойта нет | SQL injection vulnerability in modules.php in the Current_Issue module for PHP-Nuke allows remote attackers to execute arbitrary SQL commandphp-nuke · current issue module · CWE-89 | Высокая7,5 | — | 1,1 % | 14 июл. 2009 г. |
30Наблюдать | CVE-2006-3599Эксплойта нет | SQL injection vulnerability in the Nuke Advanced Classifieds module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands vphp-nuke · advanced classified module | Высокая7,5 | — | 1,1 % | 18 июл. 2006 г. |
30Наблюдать | CVE-2008-1315Proof of concept | SQL injection vulnerability in the ZClassifieds module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cat paphp-nuke · zclassifieds · CWE-89 | Высокая7,5 | — | 1,0 % | 13 мар. 2008 г. |
30Наблюдать | CVE-2008-7226Proof of concept | SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers tophp-nuke · recipe module · CWE-89 | Высокая7,5 | — | 1,0 % | 14 сент. 2009 г. |
30Наблюдать | CVE-2008-0906Proof of concept | SQL injection vulnerability in the Docum module in PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parametephp-nuke · php-nuke module docum · CWE-89 | Высокая7,5 | — | 1,0 % | 22 февр. 2008 г. |
30Наблюдать | CVE-2008-0907Proof of concept | SQL injection vulnerability in the Inhalt module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parametephp-nuke · inhalt module · CWE-89 | Высокая7,5 | — | 1,0 % | 22 февр. 2008 г. |
30Наблюдать | CVE-2008-0934Proof of concept | SQL injection vulnerability in modules.php in the NukeC 2.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands vinukec · nukec · CWE-89 | Высокая7,5 | — | 0,9 % | 25 февр. 2008 г. |
30Наблюдать | CVE-2008-0922Proof of concept | SQL injection vulnerability in the Manuales 0.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid paphp-nuke · manuales · CWE-89 | Высокая7,5 | — | 0,9 % | 22 февр. 2008 г. |
28Наблюдать | CVE-2007-1934Proof of concept | Directory traversal vulnerability in member.php in the eBoard 1.0.7 module for PHP-Nuke allows remote attackers to include and execute arbitphp-nuke · eboard module | Средняя6,8 | — | 2,5 % | 10 апр. 2007 г. |
26Наблюдать | CVE-2006-2828Proof of concept | Global variable overwrite vulnerability in PHP-Nuke allows remote attackers to conduct remote PHP file inclusion attacks via a modified phpbphp-nuke · ev | Средняя6,4 | — | 2,5 % | 5 июн. 2006 г. |
21Наблюдать | CVE-2007-3332Proof of concept | Directory traversal vulnerability in Satellite.php in Satel Lite for PhpNuke allows remote attackers to read arbitrary files via a ..php-nuke · satel lite | Средняя5,0 | — | 2,7 % | 21 июн. 2007 г. |
21Наблюдать | CVE-2006-0185Proof of concept | Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary webphp-nuke · news module | Средняя5,0 | — | 2,3 % | 12 янв. 2006 г. |
21Наблюдать | CVE-2008-3573Proof of concept | The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the ts_randomphp-nuke · php-nuke · CWE-189 | Средняя5,0 | — | 2,0 % | 10 авг. 2008 г. |
18Наблюдать | CVE-2006-3948Proof of concept | Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke INP allows remote attackers to inject arbitrary web script or HTML via tphp-nuke · inp | Средняя4,3 | — | 1,7 % | 1 авг. 2006 г. |
18Наблюдать | CVE-2009-0302Proof of concept | SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arbphp-nuke · downloads module · CWE-89 | Средняя4,6 | — | 1,5 % | 27 янв. 2009 г. |
17Наблюдать | CVE-2008-5039Proof of concept | Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inject arbitrary web scphp-nuke · league module · CWE-79 | Средняя4,3 | — | 1,5 % | 12 нояб. 2008 г. |
8Наблюдать | CVE-2006-4190Proof of concept | Directory traversal vulnerability in autohtml.php in the AutoHTML module for PHP-Nuke allows local users to include arbitrary files via a ..php-nuke · autohtml module | Низкая2,1 | — | 0,8 % | 16 авг. 2006 г. |
- CVE-2007-162638Наблюдать
PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP cod
КритическаяCVSS 9,3Proof of conceptEPSS 3 %php-nuke · iframe module23 мар. 2007 г.
- CVE-2008-476737Наблюдать
Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploadin
КритическаяCVSS 9,0Proof of conceptEPSS 4 %php-nuke · downloadsplus module28 окт. 2008 г.
- CVE-2007-103430Наблюдать
SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attacker
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %php-nuke · emporium module21 февр. 2007 г.
- CVE-2006-359830Наблюдать
SQL injection vulnerability in the Sections module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid para
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %php-nuke · sections module18 июл. 2006 г.
- CVE-2006-621730Наблюдать
PHP remote file inclusion vulnerability in formdisp.php in the Mermaid 1.2 module for PHP-Nuke allows remote attackers to execute arbitrary
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %php-nuke · mermaid module30 нояб. 2006 г.
- CVE-2008-129830Наблюдать
SQL injection vulnerability in Hadith module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cat parameter in
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php-nuke · hadith module12 мар. 2008 г.
- CVE-2008-686530Наблюдать
SQL injection vulnerability in modules.php in the Sectionsnew module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %php-nuke · sections module14 июл. 2009 г.
- CVE-2008-686630Наблюдать
SQL injection vulnerability in modules.php in the Current_Issue module for PHP-Nuke allows remote attackers to execute arbitrary SQL command
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %php-nuke · current issue module14 июл. 2009 г.
- CVE-2006-359930Наблюдать
SQL injection vulnerability in the Nuke Advanced Classifieds module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands v
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %php-nuke · advanced classified module18 июл. 2006 г.
- CVE-2008-131530Наблюдать
SQL injection vulnerability in the ZClassifieds module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cat pa
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php-nuke · zclassifieds13 мар. 2008 г.
- CVE-2008-722630Наблюдать
SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers to
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php-nuke · recipe module14 сент. 2009 г.
- CVE-2008-090630Наблюдать
SQL injection vulnerability in the Docum module in PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid paramete
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php-nuke · php-nuke module docum22 февр. 2008 г.
- CVE-2008-090730Наблюдать
SQL injection vulnerability in the Inhalt module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid paramete
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php-nuke · inhalt module22 февр. 2008 г.
- CVE-2008-093430Наблюдать
SQL injection vulnerability in modules.php in the NukeC 2.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands vi
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %nukec · nukec25 февр. 2008 г.
- CVE-2008-092230Наблюдать
SQL injection vulnerability in the Manuales 0.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid pa
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php-nuke · manuales22 февр. 2008 г.
- CVE-2007-193428Наблюдать
Directory traversal vulnerability in member.php in the eBoard 1.0.7 module for PHP-Nuke allows remote attackers to include and execute arbit
СредняяCVSS 6,8Proof of conceptEPSS 2 %php-nuke · eboard module10 апр. 2007 г.
- CVE-2006-282826Наблюдать
Global variable overwrite vulnerability in PHP-Nuke allows remote attackers to conduct remote PHP file inclusion attacks via a modified phpb
СредняяCVSS 6,4Proof of conceptEPSS 3 %php-nuke · ev5 июн. 2006 г.
- CVE-2007-333221Наблюдать
Directory traversal vulnerability in Satellite.php in Satel Lite for PhpNuke allows remote attackers to read arbitrary files via a ..
СредняяCVSS 5,0Proof of conceptEPSS 3 %php-nuke · satel lite21 июн. 2007 г.
- CVE-2006-018521Наблюдать
Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary web
СредняяCVSS 5,0Proof of conceptEPSS 2 %php-nuke · news module12 янв. 2006 г.
- CVE-2008-357321Наблюдать
The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the ts_random
СредняяCVSS 5,0Proof of conceptEPSS 2 %php-nuke · php-nuke10 авг. 2008 г.
- CVE-2006-394818Наблюдать
Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke INP allows remote attackers to inject arbitrary web script or HTML via t
СредняяCVSS 4,3Proof of conceptEPSS 2 %php-nuke · inp1 авг. 2006 г.
- CVE-2009-030218Наблюдать
SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arb
СредняяCVSS 4,6Proof of conceptEPSS 1 %php-nuke · downloads module27 янв. 2009 г.
- CVE-2008-503917Наблюдать
Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inject arbitrary web sc
СредняяCVSS 4,3Proof of conceptEPSS 1 %php-nuke · league module12 нояб. 2008 г.
- CVE-2006-41908Наблюдать
Directory traversal vulnerability in autohtml.php in the AutoHTML module for PHP-Nuke allows local users to include arbitrary files via a ..
НизкаяCVSS 2,1Proof of conceptEPSS 1 %php-nuke · autohtml module16 авг. 2006 г.