Skip to main content

Vendor archive

phpnuke CVEs

Beta · best-effort

40 CVEs tagged to vendor phpnuke2 Critical, 25 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2021-30177

Published Apr 7, 2021

There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execution. This occurs because the U.S. state is not validated to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-5083

Published Feb 14, 2012

SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter in an Add action to modules.ph…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3784

Published Sep 24, 2011

Francisco Burzi PHP-Nuke 8.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1482

Published Jun 21, 2011

Multiple cross-site request forgery (CSRF) vulnerabilities in mainfile.php in Francisco Burzi PHP-Nuke 8.0 and earlier allow remote attackers to hijack the authentication of admin…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1481

Published Jun 21, 2011

Multiple cross-site scripting (XSS) vulnerabilities in Francisco Burzi PHP-Nuke 8.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sender_na…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1480

Published Jun 21, 2011

SQL injection vulnerability in admin.php in the administration backend in Francisco Burzi PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands via th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-7226

Published Sep 14, 2009

SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-7038

Published Aug 24, 2009

SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid parameter in a showgall action to modules.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6865

Published Jul 14, 2009

SQL injection vulnerability in modules.php in the Sectionsnew module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parameter in a printpage…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1842

Published Jun 1, 2009

SQL injection vulnerability in main/tracking/userLog.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6779

Published May 1, 2009

SQL injection vulnerability in the Sarkilar module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a showcontent action to modules.p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6728

Published Apr 20, 2009

SQL injection vulnerability in the Sections module in PHP-Nuke, probably before 8.0, allows remote attackers to execute arbitrary SQL commands via the artid parameter in a printpa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5039

Published Nov 12, 2008

Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inject arbitrary web script or HTML via the tid parameter in a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4804

Published Oct 31, 2008

SQL injection vulnerability in the Gallery module 1.3 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the aid parameter in a showalbum action to index.p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3151

Published Jul 11, 2008

SQL injection vulnerability in the 4ndvddb 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a show_dvd action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1219

Published Mar 10, 2008

SQL injection vulnerability in the Kutub-i Sitte (KutubiSitte) 1.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the kid parameter in a hadisgo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1220

Published Mar 10, 2008

SQL injection vulnerability in the 4nChat 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the roomid parameter in an index action to modules…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1053

Published Feb 27, 2008

Multiple SQL injection vulnerabilities in the Kose_Yazilari module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the artid parameter in a (1) viewartic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0879

Published Feb 21, 2008

SQL injection vulnerability in modules.php in the Web_Links module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewlink actio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0880

Published Feb 21, 2008

SQL injection vulnerability in modules.php in the EasyContent module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the page_id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 40 CVEsPage 1 of 2