Записи phpnuke
40 опубликованных записей вендора phpnuke.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 23
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')22
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
40 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2021-30177Эксплойта нет | There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execution.phpnuke · php-nuke · CWE-89 | Критическая9,8 | — | 2,4 % | 7 апр. 2021 г. |
37Наблюдать | CVE-2008-4767Proof of concept | Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploadinphp-nuke · downloadsplus module · CWE-20 | Критическая9,0 | — | 4,2 % | 28 окт. 2008 г. |
36Наблюдать | CVE-2004-1842Proof of concept | Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via phpnuke · php-nuke · CWE-352 | Высокая8,8 | — | 1,7 % | 31 дек. 2004 г. |
33Наблюдать | CVE-2001-0899Proof of concept | Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variablephpnuke · php-nuke | Высокая7,5 | — | 8,9 % | 16 нояб. 2001 г. |
31Наблюдать | CVE-2006-5494Proof of concept | Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB module for PHP-Nuke allophpnuke · php-nuke · CWE-94 | Высокая7,5 | — | 3,2 % | 25 окт. 2006 г. |
31Наблюдать | CVE-2014-3934Proof of concept | SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL commands via the topphpnuke · php-nuke · CWE-89 | Высокая7,5 | — | 2,2 % | 2 июн. 2014 г. |
31Наблюдать | CVE-2008-2020Эксплойта нет | The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) my123tkshop · e-commerce-suite · CWE-330 | Высокая7,5 | — | 1,7 % | 29 апр. 2008 г. |
30Наблюдать | CVE-2008-1219Proof of concept | SQL injection vulnerability in the Kutub-i Sitte (KutubiSitte) 1.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commphpnuke · kutubisitte component · CWE-89 | Высокая7,5 | — | 1,2 % | 10 мар. 2008 г. |
30Наблюдать | CVE-2008-7038Proof of concept | SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid parphpnuke · php-nuke · CWE-89 | Высокая7,5 | — | 1,2 % | 24 авг. 2009 г. |
30Наблюдать | CVE-2011-1480Эксплойта нет | SQL injection vulnerability in admin.php in the administration backend in Francisco Burzi PHP-Nuke 8.0 and earlier allows remote attackers tphpnuke · php-nuke · CWE-89 | Высокая7,5 | — | 1,2 % | 20 июн. 2011 г. |
30Наблюдать | CVE-2008-0879Proof of concept | SQL injection vulnerability in modules.php in the Web_Links module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands viphpnuke · web links module · CWE-89 | Высокая7,5 | — | 1,1 % | 21 февр. 2008 г. |
30Наблюдать | CVE-2008-6865Эксплойта нет | SQL injection vulnerability in modules.php in the Sectionsnew module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands php-nuke · sections module · CWE-89 | Высокая7,5 | — | 1,1 % | 14 июл. 2009 г. |
30Наблюдать | CVE-2008-4804Эксплойта нет | SQL injection vulnerability in the Gallery module 1.3 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the aid parnukedgallery · gallery · CWE-89 | Высокая7,5 | — | 1,1 % | 31 окт. 2008 г. |
30Наблюдать | CVE-2008-6728Эксплойта нет | SQL injection vulnerability in the Sections module in PHP-Nuke, probably before 8.0, allows remote attackers to execute arbitrary SQL commanphpnuke · php-nuke · CWE-89 | Высокая7,5 | — | 1,1 % | 20 апр. 2009 г. |
30Наблюдать | CVE-2008-0880Proof of concept | SQL injection vulnerability in modules.php in the EasyContent module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands phpnuke · easycontent module · CWE-89 | Высокая7,5 | — | 1,1 % | 21 февр. 2008 г. |
30Наблюдать | CVE-2008-0881Proof of concept | SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands viaphpnuke · okul module · CWE-89 | Высокая7,5 | — | 1,1 % | 21 февр. 2008 г. |
30Наблюдать | CVE-2010-5083Proof of concept | SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url pphpnuke · php-nuke · CWE-89 | Высокая7,5 | — | 1,0 % | 14 февр. 2012 г. |
30Наблюдать | CVE-2007-1450Эксплойта нет | SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Topphpnuke · php-nuke | Высокая7,5 | — | 1,0 % | 14 мар. 2007 г. |
30Наблюдать | CVE-2008-3151Proof of concept | SQL injection vulnerability in the 4ndvddb 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parphpnuke · 4ndvddb · CWE-89 | Высокая7,5 | — | 1,0 % | 11 июл. 2008 г. |
30Наблюдать | CVE-2008-0827Proof of concept | SQL injection vulnerability in the Books module of PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.phpnuke · book · CWE-89 | Высокая7,5 | — | 1,0 % | 19 февр. 2008 г. |
30Наблюдать | CVE-2008-1314Proof of concept | SQL injection vulnerability in the Johannes Hass gaestebuch 2.2 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commandjohannes hass · gaestebuch module · CWE-89 | Высокая7,5 | — | 1,0 % | 12 мар. 2008 г. |
30Наблюдать | CVE-2008-7226Proof of concept | SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers tophp-nuke · recipe module · CWE-89 | Высокая7,5 | — | 1,0 % | 14 сент. 2009 г. |
30Наблюдать | CVE-2008-1053Proof of concept | Multiple SQL injection vulnerabilities in the Kose_Yazilari module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands viaphpnuke · kose yazilari module · CWE-89 | Высокая7,5 | — | 1,0 % | 27 февр. 2008 г. |
30Наблюдать | CVE-2008-6779Proof of concept | SQL injection vulnerability in the Sarkilar module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parametphpnuke · php-nuke · CWE-89 | Высокая7,5 | — | 1,0 % | 1 мая 2009 г. |
30Наблюдать | CVE-2009-1842Proof of concept | SQL injection vulnerability in main/tracking/userLog.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL cophpnuke · php-nuke · CWE-89 | Высокая7,5 | — | 1,0 % | 1 июн. 2009 г. |
- CVE-2021-3017740В плане
There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execution.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %phpnuke · php-nuke7 апр. 2021 г.
- CVE-2008-476737Наблюдать
Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploadin
КритическаяCVSS 9,0Proof of conceptEPSS 4 %php-nuke · downloadsplus module28 окт. 2008 г.
- CVE-2004-184236Наблюдать
Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %phpnuke · php-nuke31 дек. 2004 г.
- CVE-2001-089933Наблюдать
Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variable
ВысокаяCVSS 7,5Proof of conceptEPSS 9 %phpnuke · php-nuke16 нояб. 2001 г.
- CVE-2006-549431Наблюдать
Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB module for PHP-Nuke allo
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %phpnuke · php-nuke25 окт. 2006 г.
- CVE-2014-393431Наблюдать
SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL commands via the top
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %phpnuke · php-nuke2 июн. 2014 г.
- CVE-2008-202031Наблюдать
The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3)
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %my123tkshop · e-commerce-suite29 апр. 2008 г.
- CVE-2008-121930Наблюдать
SQL injection vulnerability in the Kutub-i Sitte (KutubiSitte) 1.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL comm
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpnuke · kutubisitte component10 мар. 2008 г.
- CVE-2008-703830Наблюдать
SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid par
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpnuke · php-nuke24 авг. 2009 г.
- CVE-2011-148030Наблюдать
SQL injection vulnerability in admin.php in the administration backend in Francisco Burzi PHP-Nuke 8.0 and earlier allows remote attackers t
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %phpnuke · php-nuke20 июн. 2011 г.
- CVE-2008-087930Наблюдать
SQL injection vulnerability in modules.php in the Web_Links module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands vi
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpnuke · web links module21 февр. 2008 г.
- CVE-2008-686530Наблюдать
SQL injection vulnerability in modules.php in the Sectionsnew module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %php-nuke · sections module14 июл. 2009 г.
- CVE-2008-480430Наблюдать
SQL injection vulnerability in the Gallery module 1.3 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the aid par
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %nukedgallery · gallery31 окт. 2008 г.
- CVE-2008-672830Наблюдать
SQL injection vulnerability in the Sections module in PHP-Nuke, probably before 8.0, allows remote attackers to execute arbitrary SQL comman
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %phpnuke · php-nuke20 апр. 2009 г.
- CVE-2008-088030Наблюдать
SQL injection vulnerability in modules.php in the EasyContent module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpnuke · easycontent module21 февр. 2008 г.
- CVE-2008-088130Наблюдать
SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpnuke · okul module21 февр. 2008 г.
- CVE-2010-508330Наблюдать
SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url p
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpnuke · php-nuke14 февр. 2012 г.
- CVE-2007-145030Наблюдать
SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Top
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %phpnuke · php-nuke14 мар. 2007 г.
- CVE-2008-315130Наблюдать
SQL injection vulnerability in the 4ndvddb 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id par
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpnuke · 4ndvddb11 июл. 2008 г.
- CVE-2008-082730Наблюдать
SQL injection vulnerability in the Books module of PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpnuke · book19 февр. 2008 г.
- CVE-2008-131430Наблюдать
SQL injection vulnerability in the Johannes Hass gaestebuch 2.2 module for PHP-Nuke allows remote attackers to execute arbitrary SQL command
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %johannes hass · gaestebuch module12 мар. 2008 г.
- CVE-2008-722630Наблюдать
SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers to
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %php-nuke · recipe module14 сент. 2009 г.
- CVE-2008-105330Наблюдать
Multiple SQL injection vulnerabilities in the Kose_Yazilari module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpnuke · kose yazilari module27 февр. 2008 г.
- CVE-2008-677930Наблюдать
SQL injection vulnerability in the Sarkilar module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id paramet
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpnuke · php-nuke1 мая 2009 г.
- CVE-2009-184230Наблюдать
SQL injection vulnerability in main/tracking/userLog.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL co
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %phpnuke · php-nuke1 июн. 2009 г.