📦

php-nuke

Vendor: francisco_burzi

Actively Exploited 0 CISA KEV List
PoC / Exploits 65 Code Available
Total RCEs 3 Remote Access
Total CVEs 195 Total Indexed
Avg. EPSS 3.44% Exploit Prob.
Latest CVE CVE-2021-30177 Apr 07

Security Vulnerability Index

Page 10 / 20
4.3 CVSS
CVE-2004-1985
Exploit Found

Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web script via the CPG_URL parameter.

EPSS: 3.91%
7.5 CVSS
CVE-2004-1972
Exploit Found

SQL injection vulnerability in modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to execute arbitrary SQL code via the (1) clipid or (2) catid parameters in a viewclip, viewcat, or voteclip action.

EPSS: 2.07%
7.5 CVSS
CVE-2004-1929
Exploit Found

SQL injection vulnerability in the bblogin function in functions.php in PHP-Nuke 6.x through 7.2 allows remote attackers to bypass authentication and gain access by injecting base64-encoded SQL code into the user parameter.

EPSS: 6.73%
4.3 CVSS
CVE-2004-1930
Exploit Found

Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie.

EPSS: 1.74%
7.5 CVSS
CVE-2004-1932
Exploit Found

SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter.

EPSS: 2.07%
5.0 CVSS
CVE-2004-1986
Exploit Found

Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the startdir parameter.

EPSS: 10.63%
5.0 CVSS

MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) browsers.php, (2) mstrack.php, or (3) title.php, which reveal the full path in a PHP error message.

EPSS: 1.18%
4.3 CVSS

Multiple cross-site scripting (XSS) vulnerabilities in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) screen parameter to modules.php, (2) module_name parameter to title.php, (3) sortby parameter to modules.php, or (4) overview parameter to modules.php.

EPSS: 1.24%
5.0 CVSS
CVE-2004-1830
Exploit Found

error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (3) lang parameter, which leaks the pathname in a PHP error message.

EPSS: 2.79%
4.3 CVSS
CVE-2004-1817
Exploit Found

Cross-site scripting (XSS) vulnerability in modules.php in Php-Nuke 7.1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) Your Name field, (2) e-mail field, (3) nicname field, (4) fname parameter, (5) ratenum parameter, or (6) search field.

EPSS: 1.74%