Skip to main content

Vendor/product archive

phpnuke / php-nuke CVEs

Beta · best-effort

30 CVEs tagged to phpnuke / php-nuke2 Critical, 17 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2021-30177

Published Apr 7, 2021

There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execution. This occurs because the U.S. state is not validated to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-5083

Published Feb 14, 2012

SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter in an Add action to modules.ph…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3784

Published Sep 24, 2011

Francisco Burzi PHP-Nuke 8.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1482

Published Jun 21, 2011

Multiple cross-site request forgery (CSRF) vulnerabilities in mainfile.php in Francisco Burzi PHP-Nuke 8.0 and earlier allow remote attackers to hijack the authentication of admin…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1481

Published Jun 21, 2011

Multiple cross-site scripting (XSS) vulnerabilities in Francisco Burzi PHP-Nuke 8.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sender_na…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1480

Published Jun 21, 2011

SQL injection vulnerability in admin.php in the administration backend in Francisco Burzi PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands via th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-7226

Published Sep 14, 2009

SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-7038

Published Aug 24, 2009

SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid parameter in a showgall action to modules.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6865

Published Jul 14, 2009

SQL injection vulnerability in modules.php in the Sectionsnew module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parameter in a printpage…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1842

Published Jun 1, 2009

SQL injection vulnerability in main/tracking/userLog.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6779

Published May 1, 2009

SQL injection vulnerability in the Sarkilar module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a showcontent action to modules.p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6728

Published Apr 20, 2009

SQL injection vulnerability in the Sections module in PHP-Nuke, probably before 8.0, allows remote attackers to execute arbitrary SQL commands via the artid parameter in a printpa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5039

Published Nov 12, 2008

Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inject arbitrary web script or HTML via the tid parameter in a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4804

Published Oct 31, 2008

SQL injection vulnerability in the Gallery module 1.3 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the aid parameter in a showalbum action to index.p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4212

Published Aug 8, 2007

Multiple cross-site scripting (XSS) vulnerabilities in the Search Module in PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via a trailing "<" instead of a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1519

Published Mar 20, 2007

Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke 8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the query parameter in a sea…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1520

Published Mar 20, 2007

The cross-site request forgery (CSRF) protection in PHP-Nuke 8.0 and earlier does not ensure the SERVER superglobal is an array before validating the HTTP_REFERER, which allows re…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1449

Published Mar 14, 2007

Directory traversal vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1450

Published Mar 14, 2007

SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Top or News module via the lang parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5525

Published Oct 26, 2006

Incomplete blacklist vulnerability in mainfile.php in PHP-Nuke 7.9 and earlier allows remote attackers to conduct SQL injection attacks via (1) "/**/UNION " or (2) " UNION/**/" se…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 30 CVEsPage 1 of 2