İçeriğe atla
Noroxi

nexusphp kayıtları

nexusphp üreticisine ait 14 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
3
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

14 kayıt
  • CVE-2022-46887
    45Planlayın

    Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[]

    KritikCVSS 9,8İstismar yokEPSS %19

    nexusphp · nexusphp19 Oca 2023

  • CVE-2020-24770
    40Planlayın

    SQL injection vulnerability in modrules.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    KritikCVSS 9,8İstismar yokEPSS %2

    nexusphp · nexusphp29 Mar 2022

  • CVE-2020-24769
    40Planlayın

    SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the classes par

    KritikCVSS 9,8İstismar yokEPSS %2

    nexusphp · nexusphp29 Mar 2022

  • CVE-2022-46889
    39İzleyin

    A persistent cross-site scripting (XSS) vulnerability in NexusPHP before 1.7.33 allows remote authenticated attackers to permanently inject

    OrtaCVSS 5,4İstismar yokEPSS %60

    nexusphp · nexusphp19 Oca 2023

  • CVE-2017-13669
    39İzleyin

    SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswered parameter to staffbox.php.

    KritikCVSS 9,8İstismar yokEPSS %1

    nexusphp · nexusphp24 Ağu 2017

  • CVE-2017-12679
    39İzleyin

    SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the delcheater parameter to cheaterbox.php.

    KritikCVSS 9,8İstismar yokEPSS %1

    nexusphp · nexusphp24 Ağu 2017

  • CVE-2017-14069
    39İzleyin

    SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the usernw array parameter to nowarn.php.

    KritikCVSS 9,8İstismar yokEPSS %1

    nexusphp · nexusphp31 Ağu 2017

  • CVE-2017-12981
    39İzleyin

    NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an addforum action.

    KritikCVSS 9,8İstismar yokEPSS %1

    nexusphp · nexusphp21 Ağu 2017

  • CVE-2017-14076
    39İzleyin

    SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the id parameter to linksmanage.php in an editlink action.

    KritikCVSS 9,8İstismar yokEPSS %1

    nexusphp · nexusphp31 Ağu 2017

  • CVE-2020-24771
    31İzleyin

    Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.

    YüksekCVSS 7,5İstismar yokEPSS %2

    nexusphp · nexusphp29 Mar 2022

  • CVE-2022-46888
    24İzleyin

    Multiple reflective cross-site scripting (XSS) vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to inject arbitrary web scri

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    nexusphp · nexusphp19 Oca 2023

  • CVE-2017-11651
    24İzleyin

    NexusPHP V1.5 has XSS via a javascript: or data: URL in a UBBCode url tag.

    OrtaCVSS 6,1İstismar yokEPSS %1

    nexusphp · nexusphp26 Tem 2017

  • CVE-2017-14070
    24İzleyin

    Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to ipsearch.php, related to PHP_SELF.

    OrtaCVSS 6,1İstismar yokEPSS %1

    nexusphp · nexusphp31 Ağu 2017

  • CVE-2022-46890
    17İzleyin

    Weak access control in NexusPHP before 1.7.33 allows a remote authenticated user to edit any post in the forum (this is caused by a lack of

    OrtaCVSS 4,3İstismar yokEPSS %1

    nexusphp · nexusphp19 Oca 2023