Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
php-nuke vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2008-0461
SQL injection vulnerability in index.php in the Search module in PHP-Nuke 8.0 FINAL and previous versions, when magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via the sid parameter in a comments action to modules.php. NOTE: some of t...
Francisco Burzi Php-nuke
1 EDB exploit
7.5
CVSSv2
CVE-2008-0907
SQL injection vulnerability in the Inhalt module for PHP-Nuke allows remote malicious users to execute arbitrary SQL commands via the cid parameter.
Php-nuke Inhalt Module
1 EDB exploit
7.5
CVSSv2
CVE-2008-0922
SQL injection vulnerability in the Manuales 0.1 module for PHP-Nuke allows remote malicious users to execute arbitrary SQL commands via the cid parameter in a viewdownload action to modules.php.
Php-nuke Manuales 0.1
1 EDB exploit
7.5
CVSSv2
CVE-2007-0309
SQL injection vulnerability in blocks/block-Old_Articles.php in Francisco Burzi PHP-Nuke 7.9 and previous versions, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via the cat parameter.
Francisco Burzi Php-nuke
1 EDB exploit
7.5
CVSSv2
CVE-2008-3512
SQL injection vulnerability in the Kleinanzeigen module for PHP-Nuke allows remote malicious users to execute arbitrary SQL commands via the lid parameter in a visit action to modules.php.
Php Nuke Kleinanzeigen Module
1 EDB exploit
7.5
CVSSv2
CVE-2007-1034
SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and previous versions module for PHP-Nuke allows remote malicious users to execute arbitrary SQL commands via the category_id parameter.
Php-nuke Emporium Module
2 EDB exploits
6.8
CVSSv2
CVE-2007-1061
SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and previous versions, when the "HTTP Referers" block is enabled, allows remote malicious users to execute arbitrary SQL commands via the HTTP Referer header (HTTP_REFERER variable).
Francisco Burzi Php-nuke
3 EDB exploits
9.3
CVSSv2
CVE-2007-1626
PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote malicious users to execute arbitrary PHP code via a URL in the file parameter.
Php-nuke Iframe Module
1 EDB exploit
7.5
CVSSv2
CVE-2021-30177
There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execution. This occurs because the U.S. state is not validated to be two letters, and the OrderBy field is not validated to be one of LASTNAME, CITY, or STATE.
Phpnuke Php-nuke 8.3.3
7.5
CVSSv2
CVE-2006-3598
SQL injection vulnerability in the Sections module for PHP-Nuke allows remote malicious users to execute arbitrary SQL commands via the artid parameter in a viewarticle op.
Php-nuke Sections Module
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
path traversal
CVE-2024-33545
CVE-2024-35725
CVE-2024-32704
overflow
file upload
CVE-2024-0230
CVE-2024-32705
CVE-2024-23692
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »