The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke, allow remote attackers to obtain sensitive information via a URL with an invalid argument, which reveals the full path in an error message.
📦
nukecalendar
Vendor: shiba-design
Actively Exploited
0
CISA KEV List
PoC / Exploits
3
Code Available
Total RCEs
0
Remote Access
Total CVEs
6
Total Indexed
Avg. EPSS
2.33%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
5.0
CVSS
CVE-2004-1912
Exploit Found
Severity: MEDIUM
4.3
CVSS
CVE-2004-1913
Exploit Found
Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject arbitrary web script or HTML via the eid parameter.
Severity: MEDIUM
7.5
CVSS
CVE-2004-1914
Exploit Found
SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL commands via the eid parameter.
Severity: HIGH