Vulnerability index

Browse CVEs

68 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Php Nuke MEDIUM 6.8
CVE-2004-2354

SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter…

No fix yet
Fix from $1,600 2004-12-31
Php Nuke MEDIUM 5.0
CVE-2004-1912

The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuk…

No fix yet
Fix from $1,600 2004-12-31
Php Nuke MEDIUM 5.0
CVE-2004-2019

The WebLinks module in Php-Nuke 6.x through 7.3 allows remote attackers to obtain sensitive information via an invalid show parameter, which displays…

No fix yet
Fix from $1,600 2004-12-31
Php Nuke MEDIUM 5.0
CVE-2004-2296

The preview_review function in the Reviews module in PHP-Nuke 6.0 to 7.3, when running on Windows systems, allows remote attackers to obtain sensitiv…

No fix yet
Fix from $1,600 2004-12-31
Php Nuke MEDIUM 5.0
CVE-2004-2297

The Reviews module in PHP-Nuke 6.0 to 7.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a large, out-of-range…

No fix yet
Fix from $1,600 2004-12-31
Php Nuke MEDIUM 6.8
CVE-2004-0265

Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via…

No fix yet
Fix from $1,600 2004-11-23
Php Nuke MEDIUM 6.4
CVE-2004-0269EPSS 8%

SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive in…

Patch available
Fix from $1,600 2004-11-23
Php Nuke MEDIUM 5.0
CVE-2004-0266

SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote attackers to obtain the admin…

No fix yet
Fix from $1,600 2004-11-23
Php Nuke HIGH 7.5
CVE-2004-0732

SQL injection vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to execute arbitrary SQL statements via the instor…

No fix yet
Fix from $1,950 2004-07-27
Php Nuke HIGH 7.5
CVE-2004-0737

Multiple cross-site scripting vulnerabilities in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary web script o…

Mitigation only
Fix from $1,950 2004-07-27
Php Nuke HIGH 7.5
CVE-2004-0738

Multiple SQL injection vulnerabilities in the Search module in Php-Nuke allow remote attackers to execute arbitrary SQL via the (1) min or (2) categ …

Mitigation only
Fix from $1,950 2004-07-27
Php Nuke MEDIUM 6.8
CVE-2004-0731

Cross-site scripting (XSS) vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary script as other u…

No fix yet
Fix from $1,600 2004-07-27
Php Nuke MEDIUM 5.0
CVE-2004-0736

The search module in Php-Nuke allows remote attackers to gain sensitive information via the (1) "**" or (2) "+" search patterns, which reveals the pa…

Mitigation only
Fix from $1,600 2004-07-27
Php Nuke HIGH 7.5
CVE-2004-2044EPSS 11%

PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not…

No fix yet
Fix from $1,950 2004-06-01
Php Nuke MEDIUM 5.0
CVE-2004-1998

The Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to gain sensitive information via an invalid show parameter to modules.php, …

No fix yet
Fix from $1,600 2004-05-05
Php Nuke HIGH 7.5
CVE-2004-1972

SQL injection vulnerability in modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to execute arbitrary SQL code via the …

No fix yet
Fix from $1,950 2004-04-26
Php Nuke HIGH 7.5
CVE-2004-1929EPSS 7%

SQL injection vulnerability in the bblogin function in functions.php in PHP-Nuke 6.x through 7.2 allows remote attackers to bypass authentication and…

No fix yet
Fix from $1,950 2004-04-13
Php Nuke HIGH 7.5
CVE-2004-1932

SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and c…

No fix yet
Fix from $1,950 2004-04-12
Php Nuke MEDIUM 5.0
CVE-2004-1839

MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) browsers.php, (2) mstrack.php…

Mitigation only
Fix from $1,600 2004-03-22
Php Nuke MEDIUM 5.0
CVE-2004-1830

error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or …

Mitigation only
Fix from $1,600 2004-03-18
Php Nuke HIGH 7.5
CVE-2003-1210EPSS 5%

Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands …

Fix: after 6.5
Fix from $1,950 2003-12-31
Php Nuke HIGH 7.5
CVE-2003-1435

SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search mo…

No fix yet
Fix from $1,950 2003-12-31
Php Nuke MEDIUM 5.0
CVE-2003-1526

PHP-Nuke 7.0 allows remote attackers to obtain the installation path via certain characters such as (1) ", (2) ', or (3) > in the search field, which…

No fix yet
Fix from $1,600 2003-12-31
Php Nuke MEDIUM 5.0
CVE-2002-2032EPSS 6%

sql_layer.php in PHP-Nuke 5.4 and earlier does not restrict access to debugging features, which allows remote attackers to gain SQL query information…

No fix yet
Fix from $1,600 2002-12-31
Php Nuke HIGH 7.5
CVE-2002-1242

SQL injection vulnerability in PHP-Nuke before 6.0 allows remote authenticated users to modify the database and gain privileges via the "bio" argumen…

Patch available
Fix from $1,950 2002-11-12
Php Nuke MEDIUM 5.0
CVE-2002-0483EPSS 8%

index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to…

No fix yet
Fix from $1,600 2002-08-12
Php Nuke HIGH 7.5
CVE-2002-0206EPSS 6%

index.php in Francisco Burzi PHP-Nuke 5.3.1 and earlier, and possibly other versions before 5.5, allows remote attackers to execute arbitrary PHP cod…

Mitigation only
Fix from $1,950 2002-05-16
Php Nuke MEDIUM 5.0
CVE-2001-0854

PHP-Nuke 5.2 allows remote attackers to copy and delete arbitrary files by calling case.filemanager.php with admin.php as an argument, which sets the…

Mitigation only
Fix from $1,600 2001-12-06
Php Nuke HIGH 7.5
CVE-2001-0911

PHP-Nuke 5.1 stores user and administrator passwords in a base-64 encoded cookie, which could allow remote attackers to gain privileges by stealing o…

Mitigation only
Fix from $1,950 2001-11-21
Gallery MEDIUM 5.0
CVE-2001-0900EPSS 8%

Directory traversal vulnerability in modules.php in Gallery before 1.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the in…

Fix: after 1.2.3
Fix from $1,600 2001-11-18