Vulnerability index

Browse CVEs

68 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Php Nuke HIGH 7.5
CVE-2001-1032

admin.php in PHP-Nuke 5.2 and earlier, except 5.0RC1, does not check login credentials for upload operations, which allows remote attackers to copy a…

Fix: after 5.2
Fix from $1,950 2001-09-24
Php Nuke HIGH 10.0
CVE-2001-1025

PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not alre…

No fix yet
Fix from $1,950 2001-08-31
Php Nuke MEDIUM 5.0
CVE-2001-0383EPSS 6%

banners.php in PHP-Nuke 4.4 and earlier allows remote attackers to modify banner ad URLs by directly calling the Change operation, which does not req…

Fix: after 4.4
Fix from $1,600 2001-06-18
Php Nuke HIGH 7.5
CVE-2001-0001

cookiedecode function in PHP-Nuke 4.4 allows users to bypass authentication and gain access to other user accounts by extracting the authentication i…

Patch available
Fix from $1,950 2001-06-02
Php Nuke HIGH 10.0
CVE-2001-0320

bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting …

No fix yet
Fix from $1,950 2001-05-03
Php Nuke HIGH 7.5
CVE-2001-0292

PHP-Nuke 4.4.1a allows remote attackers to modify a user's email address and obtain the password by guessing the user id (UID) and calling user.php w…

No fix yet
Fix from $1,950 2001-05-03
Php Nuke MEDIUM 5.0
CVE-2001-0321

opendir.php script in PHP-Nuke allows remote attackers to read arbitrary files by specifying the filename as an argument to the requesturl parameter.

No fix yet
Fix from $1,600 2001-05-03
Php Nuke HIGH 7.5
CVE-2000-0745EPSS 12%

admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a…

Patch available
Fix from $1,950 2000-10-20