📦

php-nuke

Vendor: francisco_burzi

Actively Exploited 0 CISA KEV List
PoC / Exploits 65 Code Available
Total RCEs 3 Remote Access
Total CVEs 195 Total Indexed
Avg. EPSS 3.44% Exploit Prob.
Latest CVE CVE-2021-30177 Apr 07

Security Vulnerability Index

Page 8 / 20
7.5 CVSS
CVE-2004-2018
Exploit Found

PHP remote file inclusion vulnerability in index.php in Php-Nuke 6.x through 7.3 allows remote attackers to execute arbitrary PHP code by modifying the modpath parameter to reference a URL on a remote web server that contains the code.

EPSS: 3.78%
7.5 CVSS
CVE-2004-1914
Exploit Found

SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL commands via the eid parameter.

EPSS: 1.75%
4.3 CVSS
CVE-2004-1913
Exploit Found

Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject arbitrary web script or HTML via the eid parameter.

EPSS: 1.73%
5.0 CVSS
CVE-2004-1912
Exploit Found

The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke, allow remote attackers to obtain sensitive information via a URL with an invalid argument, which reveals the full path in an error message.

EPSS: 3.51%
6.4 CVSS
CVE-2004-0269
Exploit Found

SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module.

EPSS: 8.09%
5.0 CVSS
CVE-2004-0266
Exploit Found

SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote attackers to obtain the administrator password via the c_mid parameter.

EPSS: 2.05%
6.8 CVSS
CVE-2004-0265
Exploit Found

Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in the News or Reviews modules.

EPSS: 4.63%
7.5 CVSS

Multiple SQL injection vulnerabilities in the Search module in Php-Nuke allow remote attackers to execute arbitrary SQL via the (1) min or (2) categ parameters.

EPSS: 1.38%
7.5 CVSS

Multiple cross-site scripting vulnerabilities in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) max, (3) sel1, (4) sel2, (5) sel3, (6) sel4, (7) sel5, (8) match, (9) mod1, (10) mod2, or (11) mod3 parameters.

EPSS: 1.91%
5.0 CVSS

The search module in Php-Nuke allows remote attackers to gain sensitive information via the (1) "**" or (2) "+" search patterns, which reveals the path in an error message.

EPSS: 1.18%