php-nuke kayıtları
php-nuke üreticisine ait 24 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 15
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')11
- CWE-189 Numeric Errors1
- CWE-20 Improper Input Validation1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
24 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
38İzleyin | CVE-2007-1626Kavram kanıtı | PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP codphp-nuke · iframe module | Kritik9,3 | — | %3,1 | 23 Mar 2007 |
37İzleyin | CVE-2008-4767Kavram kanıtı | Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploadinphp-nuke · downloadsplus module · CWE-20 | Kritik9,0 | — | %4,2 | 28 Eki 2008 |
30İzleyin | CVE-2007-1034Kavram kanıtı | SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attackerphp-nuke · emporium module · CWE-89 | Yüksek7,5 | — | %1,6 | 21 Şub 2007 |
30İzleyin | CVE-2006-3598İstismar yok | SQL injection vulnerability in the Sections module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid paraphp-nuke · sections module | Yüksek7,5 | — | %1,4 | 18 Tem 2006 |
30İzleyin | CVE-2006-6217İstismar yok | PHP remote file inclusion vulnerability in formdisp.php in the Mermaid 1.2 module for PHP-Nuke allows remote attackers to execute arbitrary php-nuke · mermaid module | Yüksek7,5 | — | %1,3 | 30 Kas 2006 |
30İzleyin | CVE-2008-1298Kavram kanıtı | SQL injection vulnerability in Hadith module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cat parameter inphp-nuke · hadith module · CWE-89 | Yüksek7,5 | — | %1,2 | 12 Mar 2008 |
30İzleyin | CVE-2008-6865İstismar yok | SQL injection vulnerability in modules.php in the Sectionsnew module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands php-nuke · sections module · CWE-89 | Yüksek7,5 | — | %1,1 | 14 Tem 2009 |
30İzleyin | CVE-2008-6866İstismar yok | SQL injection vulnerability in modules.php in the Current_Issue module for PHP-Nuke allows remote attackers to execute arbitrary SQL commandphp-nuke · current issue module · CWE-89 | Yüksek7,5 | — | %1,1 | 14 Tem 2009 |
30İzleyin | CVE-2006-3599İstismar yok | SQL injection vulnerability in the Nuke Advanced Classifieds module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands vphp-nuke · advanced classified module | Yüksek7,5 | — | %1,1 | 18 Tem 2006 |
30İzleyin | CVE-2008-1315Kavram kanıtı | SQL injection vulnerability in the ZClassifieds module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cat paphp-nuke · zclassifieds · CWE-89 | Yüksek7,5 | — | %1,0 | 13 Mar 2008 |
30İzleyin | CVE-2008-7226Kavram kanıtı | SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers tophp-nuke · recipe module · CWE-89 | Yüksek7,5 | — | %1,0 | 14 Eyl 2009 |
30İzleyin | CVE-2008-0906Kavram kanıtı | SQL injection vulnerability in the Docum module in PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parametephp-nuke · php-nuke module docum · CWE-89 | Yüksek7,5 | — | %1,0 | 22 Şub 2008 |
30İzleyin | CVE-2008-0907Kavram kanıtı | SQL injection vulnerability in the Inhalt module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parametephp-nuke · inhalt module · CWE-89 | Yüksek7,5 | — | %1,0 | 22 Şub 2008 |
30İzleyin | CVE-2008-0934Kavram kanıtı | SQL injection vulnerability in modules.php in the NukeC 2.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands vinukec · nukec · CWE-89 | Yüksek7,5 | — | %0,9 | 25 Şub 2008 |
30İzleyin | CVE-2008-0922Kavram kanıtı | SQL injection vulnerability in the Manuales 0.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid paphp-nuke · manuales · CWE-89 | Yüksek7,5 | — | %0,9 | 22 Şub 2008 |
28İzleyin | CVE-2007-1934Kavram kanıtı | Directory traversal vulnerability in member.php in the eBoard 1.0.7 module for PHP-Nuke allows remote attackers to include and execute arbitphp-nuke · eboard module | Orta6,8 | — | %2,5 | 10 Nis 2007 |
26İzleyin | CVE-2006-2828Kavram kanıtı | Global variable overwrite vulnerability in PHP-Nuke allows remote attackers to conduct remote PHP file inclusion attacks via a modified phpbphp-nuke · ev | Orta6,4 | — | %2,5 | 5 Haz 2006 |
21İzleyin | CVE-2007-3332Kavram kanıtı | Directory traversal vulnerability in Satellite.php in Satel Lite for PhpNuke allows remote attackers to read arbitrary files via a ..php-nuke · satel lite | Orta5,0 | — | %2,7 | 21 Haz 2007 |
21İzleyin | CVE-2006-0185Kavram kanıtı | Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary webphp-nuke · news module | Orta5,0 | — | %2,3 | 12 Oca 2006 |
21İzleyin | CVE-2008-3573Kavram kanıtı | The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the ts_randomphp-nuke · php-nuke · CWE-189 | Orta5,0 | — | %2,0 | 10 Ağu 2008 |
18İzleyin | CVE-2006-3948Kavram kanıtı | Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke INP allows remote attackers to inject arbitrary web script or HTML via tphp-nuke · inp | Orta4,3 | — | %1,7 | 1 Ağu 2006 |
18İzleyin | CVE-2009-0302Kavram kanıtı | SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arbphp-nuke · downloads module · CWE-89 | Orta4,6 | — | %1,5 | 27 Oca 2009 |
17İzleyin | CVE-2008-5039Kavram kanıtı | Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inject arbitrary web scphp-nuke · league module · CWE-79 | Orta4,3 | — | %1,5 | 12 Kas 2008 |
8İzleyin | CVE-2006-4190Kavram kanıtı | Directory traversal vulnerability in autohtml.php in the AutoHTML module for PHP-Nuke allows local users to include arbitrary files via a ..php-nuke · autohtml module | Düşük2,1 | — | %0,8 | 16 Ağu 2006 |
- CVE-2007-162638İzleyin
PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP cod
KritikCVSS 9,3Kavram kanıtıEPSS %3php-nuke · iframe module23 Mar 2007
- CVE-2008-476737İzleyin
Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploadin
KritikCVSS 9,0Kavram kanıtıEPSS %4php-nuke · downloadsplus module28 Eki 2008
- CVE-2007-103430İzleyin
SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attacker
YüksekCVSS 7,5Kavram kanıtıEPSS %2php-nuke · emporium module21 Şub 2007
- CVE-2006-359830İzleyin
SQL injection vulnerability in the Sections module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid para
YüksekCVSS 7,5İstismar yokEPSS %1php-nuke · sections module18 Tem 2006
- CVE-2006-621730İzleyin
PHP remote file inclusion vulnerability in formdisp.php in the Mermaid 1.2 module for PHP-Nuke allows remote attackers to execute arbitrary
YüksekCVSS 7,5İstismar yokEPSS %1php-nuke · mermaid module30 Kas 2006
- CVE-2008-129830İzleyin
SQL injection vulnerability in Hadith module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cat parameter in
YüksekCVSS 7,5Kavram kanıtıEPSS %1php-nuke · hadith module12 Mar 2008
- CVE-2008-686530İzleyin
SQL injection vulnerability in modules.php in the Sectionsnew module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5İstismar yokEPSS %1php-nuke · sections module14 Tem 2009
- CVE-2008-686630İzleyin
SQL injection vulnerability in modules.php in the Current_Issue module for PHP-Nuke allows remote attackers to execute arbitrary SQL command
YüksekCVSS 7,5İstismar yokEPSS %1php-nuke · current issue module14 Tem 2009
- CVE-2006-359930İzleyin
SQL injection vulnerability in the Nuke Advanced Classifieds module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands v
YüksekCVSS 7,5İstismar yokEPSS %1php-nuke · advanced classified module18 Tem 2006
- CVE-2008-131530İzleyin
SQL injection vulnerability in the ZClassifieds module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cat pa
YüksekCVSS 7,5Kavram kanıtıEPSS %1php-nuke · zclassifieds13 Mar 2008
- CVE-2008-722630İzleyin
SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers to
YüksekCVSS 7,5Kavram kanıtıEPSS %1php-nuke · recipe module14 Eyl 2009
- CVE-2008-090630İzleyin
SQL injection vulnerability in the Docum module in PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid paramete
YüksekCVSS 7,5Kavram kanıtıEPSS %1php-nuke · php-nuke module docum22 Şub 2008
- CVE-2008-090730İzleyin
SQL injection vulnerability in the Inhalt module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid paramete
YüksekCVSS 7,5Kavram kanıtıEPSS %1php-nuke · inhalt module22 Şub 2008
- CVE-2008-093430İzleyin
SQL injection vulnerability in modules.php in the NukeC 2.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands vi
YüksekCVSS 7,5Kavram kanıtıEPSS %1nukec · nukec25 Şub 2008
- CVE-2008-092230İzleyin
SQL injection vulnerability in the Manuales 0.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid pa
YüksekCVSS 7,5Kavram kanıtıEPSS %1php-nuke · manuales22 Şub 2008
- CVE-2007-193428İzleyin
Directory traversal vulnerability in member.php in the eBoard 1.0.7 module for PHP-Nuke allows remote attackers to include and execute arbit
OrtaCVSS 6,8Kavram kanıtıEPSS %2php-nuke · eboard module10 Nis 2007
- CVE-2006-282826İzleyin
Global variable overwrite vulnerability in PHP-Nuke allows remote attackers to conduct remote PHP file inclusion attacks via a modified phpb
OrtaCVSS 6,4Kavram kanıtıEPSS %3php-nuke · ev5 Haz 2006
- CVE-2007-333221İzleyin
Directory traversal vulnerability in Satellite.php in Satel Lite for PhpNuke allows remote attackers to read arbitrary files via a ..
OrtaCVSS 5,0Kavram kanıtıEPSS %3php-nuke · satel lite21 Haz 2007
- CVE-2006-018521İzleyin
Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary web
OrtaCVSS 5,0Kavram kanıtıEPSS %2php-nuke · news module12 Oca 2006
- CVE-2008-357321İzleyin
The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the ts_random
OrtaCVSS 5,0Kavram kanıtıEPSS %2php-nuke · php-nuke10 Ağu 2008
- CVE-2006-394818İzleyin
Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke INP allows remote attackers to inject arbitrary web script or HTML via t
OrtaCVSS 4,3Kavram kanıtıEPSS %2php-nuke · inp1 Ağu 2006
- CVE-2009-030218İzleyin
SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arb
OrtaCVSS 4,6Kavram kanıtıEPSS %1php-nuke · downloads module27 Oca 2009
- CVE-2008-503917İzleyin
Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inject arbitrary web sc
OrtaCVSS 4,3Kavram kanıtıEPSS %1php-nuke · league module12 Kas 2008
- CVE-2006-41908İzleyin
Directory traversal vulnerability in autohtml.php in the AutoHTML module for PHP-Nuke allows local users to include arbitrary files via a ..
DüşükCVSS 2,1Kavram kanıtıEPSS %1php-nuke · autohtml module16 Ağu 2006