phpnuke kayıtları
phpnuke üreticisine ait 40 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 23
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')22
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
40 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2021-30177İstismar yok | There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execution.phpnuke · php-nuke · CWE-89 | Kritik9,8 | — | %2,4 | 7 Nis 2021 |
37İzleyin | CVE-2008-4767Kavram kanıtı | Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploadinphp-nuke · downloadsplus module · CWE-20 | Kritik9,0 | — | %4,2 | 28 Eki 2008 |
36İzleyin | CVE-2004-1842Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via phpnuke · php-nuke · CWE-352 | Yüksek8,8 | — | %1,7 | 31 Ara 2004 |
33İzleyin | CVE-2001-0899Kavram kanıtı | Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variablephpnuke · php-nuke | Yüksek7,5 | — | %8,9 | 16 Kas 2001 |
31İzleyin | CVE-2006-5494Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB module for PHP-Nuke allophpnuke · php-nuke · CWE-94 | Yüksek7,5 | — | %3,2 | 25 Eki 2006 |
31İzleyin | CVE-2014-3934Kavram kanıtı | SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL commands via the topphpnuke · php-nuke · CWE-89 | Yüksek7,5 | — | %2,2 | 2 Haz 2014 |
31İzleyin | CVE-2008-2020İstismar yok | The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) my123tkshop · e-commerce-suite · CWE-330 | Yüksek7,5 | — | %1,7 | 29 Nis 2008 |
30İzleyin | CVE-2008-1219Kavram kanıtı | SQL injection vulnerability in the Kutub-i Sitte (KutubiSitte) 1.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commphpnuke · kutubisitte component · CWE-89 | Yüksek7,5 | — | %1,2 | 10 Mar 2008 |
30İzleyin | CVE-2008-7038Kavram kanıtı | SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid parphpnuke · php-nuke · CWE-89 | Yüksek7,5 | — | %1,2 | 24 Ağu 2009 |
30İzleyin | CVE-2011-1480İstismar yok | SQL injection vulnerability in admin.php in the administration backend in Francisco Burzi PHP-Nuke 8.0 and earlier allows remote attackers tphpnuke · php-nuke · CWE-89 | Yüksek7,5 | — | %1,2 | 20 Haz 2011 |
30İzleyin | CVE-2008-0879Kavram kanıtı | SQL injection vulnerability in modules.php in the Web_Links module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands viphpnuke · web links module · CWE-89 | Yüksek7,5 | — | %1,1 | 21 Şub 2008 |
30İzleyin | CVE-2008-6865İstismar yok | SQL injection vulnerability in modules.php in the Sectionsnew module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands php-nuke · sections module · CWE-89 | Yüksek7,5 | — | %1,1 | 14 Tem 2009 |
30İzleyin | CVE-2008-4804İstismar yok | SQL injection vulnerability in the Gallery module 1.3 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the aid parnukedgallery · gallery · CWE-89 | Yüksek7,5 | — | %1,1 | 31 Eki 2008 |
30İzleyin | CVE-2008-6728İstismar yok | SQL injection vulnerability in the Sections module in PHP-Nuke, probably before 8.0, allows remote attackers to execute arbitrary SQL commanphpnuke · php-nuke · CWE-89 | Yüksek7,5 | — | %1,1 | 20 Nis 2009 |
30İzleyin | CVE-2010-5083Kavram kanıtı | SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url pphpnuke · php-nuke · CWE-89 | Yüksek7,5 | — | %1,1 | 14 Şub 2012 |
30İzleyin | CVE-2008-0880Kavram kanıtı | SQL injection vulnerability in modules.php in the EasyContent module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands phpnuke · easycontent module · CWE-89 | Yüksek7,5 | — | %1,1 | 21 Şub 2008 |
30İzleyin | CVE-2008-0881Kavram kanıtı | SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands viaphpnuke · okul module · CWE-89 | Yüksek7,5 | — | %1,1 | 21 Şub 2008 |
30İzleyin | CVE-2007-1450İstismar yok | SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Topphpnuke · php-nuke | Yüksek7,5 | — | %1,0 | 14 Mar 2007 |
30İzleyin | CVE-2008-3151Kavram kanıtı | SQL injection vulnerability in the 4ndvddb 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parphpnuke · 4ndvddb · CWE-89 | Yüksek7,5 | — | %1,0 | 11 Tem 2008 |
30İzleyin | CVE-2008-0827Kavram kanıtı | SQL injection vulnerability in the Books module of PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.phpnuke · book · CWE-89 | Yüksek7,5 | — | %1,0 | 19 Şub 2008 |
30İzleyin | CVE-2008-1314Kavram kanıtı | SQL injection vulnerability in the Johannes Hass gaestebuch 2.2 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commandjohannes hass · gaestebuch module · CWE-89 | Yüksek7,5 | — | %1,0 | 12 Mar 2008 |
30İzleyin | CVE-2008-7226Kavram kanıtı | SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers tophp-nuke · recipe module · CWE-89 | Yüksek7,5 | — | %1,0 | 14 Eyl 2009 |
30İzleyin | CVE-2008-1053Kavram kanıtı | Multiple SQL injection vulnerabilities in the Kose_Yazilari module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands viaphpnuke · kose yazilari module · CWE-89 | Yüksek7,5 | — | %1,0 | 27 Şub 2008 |
30İzleyin | CVE-2008-6779Kavram kanıtı | SQL injection vulnerability in the Sarkilar module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parametphpnuke · php-nuke · CWE-89 | Yüksek7,5 | — | %1,0 | 1 May 2009 |
30İzleyin | CVE-2009-1842Kavram kanıtı | SQL injection vulnerability in main/tracking/userLog.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL cophpnuke · php-nuke · CWE-89 | Yüksek7,5 | — | %1,0 | 1 Haz 2009 |
- CVE-2021-3017740Planlayın
There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execution.
KritikCVSS 9,8İstismar yokEPSS %2phpnuke · php-nuke7 Nis 2021
- CVE-2008-476737İzleyin
Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploadin
KritikCVSS 9,0Kavram kanıtıEPSS %4php-nuke · downloadsplus module28 Eki 2008
- CVE-2004-184236İzleyin
Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via
YüksekCVSS 8,8Kavram kanıtıEPSS %2phpnuke · php-nuke31 Ara 2004
- CVE-2001-089933İzleyin
Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variable
YüksekCVSS 7,5Kavram kanıtıEPSS %9phpnuke · php-nuke16 Kas 2001
- CVE-2006-549431İzleyin
Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB module for PHP-Nuke allo
YüksekCVSS 7,5Kavram kanıtıEPSS %3phpnuke · php-nuke25 Eki 2006
- CVE-2014-393431İzleyin
SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL commands via the top
YüksekCVSS 7,5Kavram kanıtıEPSS %2phpnuke · php-nuke2 Haz 2014
- CVE-2008-202031İzleyin
The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3)
YüksekCVSS 7,5İstismar yokEPSS %2my123tkshop · e-commerce-suite29 Nis 2008
- CVE-2008-121930İzleyin
SQL injection vulnerability in the Kutub-i Sitte (KutubiSitte) 1.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL comm
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpnuke · kutubisitte component10 Mar 2008
- CVE-2008-703830İzleyin
SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid par
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpnuke · php-nuke24 Ağu 2009
- CVE-2011-148030İzleyin
SQL injection vulnerability in admin.php in the administration backend in Francisco Burzi PHP-Nuke 8.0 and earlier allows remote attackers t
YüksekCVSS 7,5İstismar yokEPSS %1phpnuke · php-nuke20 Haz 2011
- CVE-2008-087930İzleyin
SQL injection vulnerability in modules.php in the Web_Links module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands vi
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpnuke · web links module21 Şub 2008
- CVE-2008-686530İzleyin
SQL injection vulnerability in modules.php in the Sectionsnew module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5İstismar yokEPSS %1php-nuke · sections module14 Tem 2009
- CVE-2008-480430İzleyin
SQL injection vulnerability in the Gallery module 1.3 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the aid par
YüksekCVSS 7,5İstismar yokEPSS %1nukedgallery · gallery31 Eki 2008
- CVE-2008-672830İzleyin
SQL injection vulnerability in the Sections module in PHP-Nuke, probably before 8.0, allows remote attackers to execute arbitrary SQL comman
YüksekCVSS 7,5İstismar yokEPSS %1phpnuke · php-nuke20 Nis 2009
- CVE-2010-508330İzleyin
SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url p
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpnuke · php-nuke14 Şub 2012
- CVE-2008-088030İzleyin
SQL injection vulnerability in modules.php in the EasyContent module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpnuke · easycontent module21 Şub 2008
- CVE-2008-088130İzleyin
SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpnuke · okul module21 Şub 2008
- CVE-2007-145030İzleyin
SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Top
YüksekCVSS 7,5İstismar yokEPSS %1phpnuke · php-nuke14 Mar 2007
- CVE-2008-315130İzleyin
SQL injection vulnerability in the 4ndvddb 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id par
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpnuke · 4ndvddb11 Tem 2008
- CVE-2008-082730İzleyin
SQL injection vulnerability in the Books module of PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpnuke · book19 Şub 2008
- CVE-2008-131430İzleyin
SQL injection vulnerability in the Johannes Hass gaestebuch 2.2 module for PHP-Nuke allows remote attackers to execute arbitrary SQL command
YüksekCVSS 7,5Kavram kanıtıEPSS %1johannes hass · gaestebuch module12 Mar 2008
- CVE-2008-722630İzleyin
SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers to
YüksekCVSS 7,5Kavram kanıtıEPSS %1php-nuke · recipe module14 Eyl 2009
- CVE-2008-105330İzleyin
Multiple SQL injection vulnerabilities in the Kose_Yazilari module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpnuke · kose yazilari module27 Şub 2008
- CVE-2008-677930İzleyin
SQL injection vulnerability in the Sarkilar module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id paramet
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpnuke · php-nuke1 May 2009
- CVE-2009-184230İzleyin
SQL injection vulnerability in main/tracking/userLog.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL co
YüksekCVSS 7,5Kavram kanıtıEPSS %1phpnuke · php-nuke1 Haz 2009