Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.6% | — | Francisco Burzi Php-nuke | 15/12/2007 | 16/6/2026 | Directory traversal vulnerability in autohtml.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the filename parameter, a different vector than CVE-2006-4190. NOTE: the provenance of this information is unknown; the details are obtained… | |
| Modificada | Media (5.1) | 0.57% | — | Francisco Burzi Php-nuke | 21/9/2007 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in admin.php in Francisco Burzi PHP-Nuke allows remote attackers to add administrative accounts via an AddAuthor action with modified add_name and add_radminsuper parameters. | |
| Modificada | Media (4.3) | 1.0% | — | Phpnuke Php-nuke | 8/8/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Search Module in PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via a trailing "<" instead of a ">" in (1) the onerror attribute of an IMG element, (2) the onload attribute of an IFRAME element, or (3) redirect users to other sites via… | |
| Modificada | Media (5) | 2.7% | — | Php-nuke Satel Lite | 21/6/2007 | 16/6/2026 | Directory traversal vulnerability in Satellite.php in Satel Lite for PhpNuke allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the name parameter in a modload action. | |
| Modificada | Media (6.8) | 2.5% | — | Php-nuke Eboard Module | 10/4/2007 | 16/6/2026 | Directory traversal vulnerability in member.php in the eBoard 1.0.7 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[name] parameter. | |
| Modificada | Alta (9.3) | 3.1% | — | Php-nuke Iframe Module | 23/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Phpnuke Php-nuke | 20/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke 8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search operation in the Downloads module, a different product than CVE-2006-3948. | |
| Modificada | Media (6.8) | 0.78% | — | Phpnuke Php-nuke | 20/3/2007 | 16/6/2026 | The cross-site request forgery (CSRF) protection in PHP-Nuke 8.0 and earlier does not ensure the SERVER superglobal is an array before validating the HTTP_REFERER, which allows remote attackers to conduct CSRF attacks. | |
| Modificada | Media (4.3) | 1.3% | — | Phpnuke Php-nuke | 14/3/2007 | 16/6/2026 | Directory traversal vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter. | |
| Modificada | Alta (7.5) | 1.0% | — | Phpnuke Php-nuke | 14/3/2007 | 16/6/2026 | SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Top or News module via the lang parameter. | |
| Modificada | Media (6.8) | 62% | — | Francisco Burzi Php-nuke | 22/2/2007 | 16/6/2026 | SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" block is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header (HTTP_REFERER variable). | |
| Modificada | Alta (7.5) | 1.6% | — | Php-nuke Emporium Module | 21/2/2007 | 16/6/2026 | SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category_id parameter. | |
| Modificada | Alta (7.5) | 4.0% | — | Francisco Burzi Php-nuke | 19/1/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 7.9 allow remote attackers to execute arbitrary SQL commands via (1) the active parameter in admin/modules/modules.php; the (2) ad_class, (3) imageurl, (4) clickurl, (5) ad_code, or (6) position parameter in modules/Advertising/admin/index.php; or… | |
| Modificada | Alta (7.5) | 4.7% | — | Francisco Burzi Php-nuke | 18/1/2007 | 16/6/2026 | SQL injection vulnerability in blocks/block-Old_Articles.php in Francisco Burzi PHP-Nuke 7.9 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |
| Modificada | Alta (7.5) | 2.0% | — | Francisco Burzi Php-nuke | 2/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in the Content module in PHP-Nuke 6.0, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via (1) the cid parameter in a list_pages_categories action or (2) the pid parameter in a showpage action. | |
| Modificada | Alta (7.5) | 1.3% | — | Php-nuke Mermaid Module | 1/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in formdisp.php in the Mermaid 1.2 module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the module_name parameter. | |
| Modificada | Alta (7.5) | 3.4% | — | Francisco Burzi Php-nuke | 1/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in the (1) rate_article and (2) rate_complete functions in modules/News/index.php in the News module in Francisco Burzi PHP-Nuke 7.9 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the sid parameter. | |
| Modificada | Alta (7.5) | 2.0% | — | Francisco Burzi Php-nuke | 4/11/2006 | 16/6/2026 | SQL injection vulnerability in modules/journal/search.php in the Journal module in Francisco Burzi PHP-Nuke 7.9 and earlier allows remote attackers to execute arbitrary SQL commands via the forwhat parameter. | |
| Modificada | Media (5.1) | 1.1% | — | Phpnuke Php-nuke | 26/10/2006 | 16/6/2026 | Incomplete blacklist vulnerability in mainfile.php in PHP-Nuke 7.9 and earlier allows remote attackers to conduct SQL injection attacks via (1) "/**/UNION " or (2) " UNION/**/" sequences, which are not rejected by the protection mechanism, as demonstrated by a SQL injection via the eid parameter in a search action in… | |
| Modificada | Alta (7.5) | 3.2% | — | Phpnuke Php-nuke | 25/10/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB module for PHP-Nuke allow remote attackers to execute arbitrary PHP code via a URL in the (1) adminpath or (2) basepath parameters. NOTE: this issue might overlap CVE-2006-6795. | |
| Modificada | Baja (2.1) | 0.85% | — | Php-nuke Autohtml Module | 17/8/2006 | 16/6/2026 | Directory traversal vulnerability in autohtml.php in the AutoHTML module for PHP-Nuke allows local users to include arbitrary files via a .. (dot dot) in the name parameter for a modload operation. | |
| Modificada | Media (4.3) | 1.7% | — | Php-nuke INP | 1/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke INP allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Php-nuke Advanced Classified Module | 18/7/2006 | 16/6/2026 | SQL injection vulnerability in the Nuke Advanced Classifieds module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id_ads parameter in an EditAds op. | |
| Modificada | Alta (7.5) | 1.4% | — | Php-nuke Sections Module | 18/7/2006 | 16/6/2026 | SQL injection vulnerability in the Sections module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parameter in a viewarticle op. | |
| Modificada | Media (6.4) | 2.5% | — | Php-nuke EV | 5/6/2006 | 16/6/2026 | Global variable overwrite vulnerability in PHP-Nuke allows remote attackers to conduct remote PHP file inclusion attacks via a modified phpbb_root_path parameter to the admin scripts (1) index.php, (2) admin_ug_auth.php, (3) admin_board.php, (4) admin_disallow.php, (5) admin_forumauth.php, (6) admin_groups.php, (7)… |