Francisco Burzi
Francisco Burzi Php-nuke: vulnerabilidades y CVE
Francisco Burzi Php-nuke tiene 94 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE94
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2008-0461 | Media (6.8) | 2.0% | — | 25 ene 2008 | SQL injection vulnerability in index.php in the Search module in PHP-Nuke 8.0 FINAL and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the sid parameter in a… |
| CVE-2007-6376 | Alta (7.5) | 2.6% | — | 15 dic 2007 | Directory traversal vulnerability in autohtml.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the filename parameter, a different vector… |
| CVE-2007-5032 | Media (5.1) | 0.57% | — | 21 sept 2007 | Cross-site request forgery (CSRF) vulnerability in admin.php in Francisco Burzi PHP-Nuke allows remote attackers to add administrative accounts via an AddAuthor action with modified add_name and add_radminsuper… |
| CVE-2007-1061 | Media (6.8) | 62% | — | 22 feb 2007 | SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" block is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer… |
| CVE-2007-0372 | Alta (7.5) | 4.0% | — | 19 ene 2007 | Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 7.9 allow remote attackers to execute arbitrary SQL commands via (1) the active parameter in admin/modules/modules.php; the (2) ad_class, (3) imageurl,… |
| CVE-2007-0309 | Alta (7.5) | 4.7% | — | 18 ene 2007 | SQL injection vulnerability in blocks/block-Old_Articles.php in Francisco Burzi PHP-Nuke 7.9 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary… |
| CVE-2006-6234 | Alta (7.5) | 2.0% | — | 2 dic 2006 | Multiple SQL injection vulnerabilities in the Content module in PHP-Nuke 6.0, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via (1) the cid parameter in a list_pages_categories… |
| CVE-2006-6200 | Alta (7.5) | 3.4% | — | 1 dic 2006 | Multiple SQL injection vulnerabilities in the (1) rate_article and (2) rate_complete functions in modules/News/index.php in the News module in Francisco Burzi PHP-Nuke 7.9 and earlier, when magic_quotes_gpc is disabled,… |
| CVE-2006-5720 | Alta (7.5) | 2.0% | — | 4 nov 2006 | SQL injection vulnerability in modules/journal/search.php in the Journal module in Francisco Burzi PHP-Nuke 7.9 and earlier allows remote attackers to execute arbitrary SQL commands via the forwhat parameter. |
| CVE-2006-1847 | Alta (7.5) | 1.5% | — | 19 abr 2006 | SQL injection vulnerability in the Your_Account module in PHP-Nuke 7.8 might allows remote attackers to execute arbitrary SQL commands via the user_id parameter in the Your_Home functionality. NOTE: the provenance of… |
| CVE-2006-1846 | Media (4.3) | 1.2% | — | 19 abr 2006 | Cross-site scripting (XSS) vulnerability in the Your_Account module in PHP-Nuke 7.8 might allows remote attackers to inject arbitrary HTML and web script via the ublock parameter, which is saved in the user's personal… |
| CVE-2006-0908 | Alta (7.5) | 1.8% | — | 28 feb 2006 | PHP-Nuke 7.8 Patched 3.2 allows remote attackers to bypass SQL injection protection mechanisms via /%2a (/*) sequences with the "ad_click" word in the query string, as demonstrated via the kala parameter. |
| CVE-2006-0907 | Alta (7.5) | 1.7% | — | 28 feb 2006 | SQL injection vulnerability in PHP-Nuke before 7.8 Patched 3.2 allows remote attackers to execute arbitrary SQL commands via encoded /%2a (/*) sequences in the query string, which bypasses regular expressions that are… |
| CVE-2006-0805 | Alta (7.5) | 3.0% | — | 21 feb 2006 | The CAPTCHA functionality in php-Nuke 6.0 through 7.9 uses fixed challenge/response pairs that only vary once per day based on the User Agent (HTTP_USER_AGENT), which allows remote attackers to bypass CAPTCHA controls… |
| CVE-2006-0676 | Media (4.3) | 2.0% | — | 13 feb 2006 | Cross-site scripting (XSS) vulnerability in header.php in PHP-Nuke 6.0 to 7.8 allows remote attackers to inject arbitrary web script or HTML via the pagetitle parameter. |
| CVE-2005-4715 | Alta (7.5) | 3.8% | — | 31 dic 2005 | Multiple SQL injection vulnerabilities in modules.php in PHP-Nuke 7.8, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) sid, and (3) pid parameters in a… |
| CVE-2005-4260 | Media (4.3) | 2.1% | — | 15 dic 2005 | Interpretation conflict in includes/mainfile.php in PHP-Nuke 7.9 and later allows remote attackers to perform cross-site scripting (XSS) attacks by replacing the ">" in the tag with a "<", which bypasses the regular… |
| CVE-2005-3792 | Alta (7.5) | 44% | — | 24 nov 2005 | Multiple SQL injection vulnerabilities in the Search module in PHP-Nuke 7.8, and possibly other versions before 7.9 with patch 3.1, allows remote attackers to execute arbitrary SQL commands, as demonstrated via the… |
| CVE-2005-3304 | Alta (7.5) | 5.6% | — | 26 oct 2005 | Multiple SQL injection vulnerabilities in PHP-Nuke 7.8 allow remote attackers to modify SQL queries and execute arbitrary PHP code via (1) the username parameter in the Your Account page, (2) the url parameter in the… |
| CVE-2005-3016 | Alta (10) | 1.4% | — | 21 sept 2005 | Multiple unspecified vulnerabilities in the WYSIWYG editor in PHP-Nuke before 7.9 Final have unknown impact and attack vectors. |
| CVE-2005-1386 | Media (5) | 1.2% | — | 3 may 2005 | PHP-Nuke 7.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) ipban.php, (2) db.php, (3) lang-norwegian.php, (4) lang-indonesian.php, (5) lang-greek.php, (6) a request to… |
| CVE-2005-1000 | Media (4.3) | 1.8% | — | 2 may 2005 | Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the bid parameter to the EmailStats op in banners.pgp, (2) the ratenum parameter… |
| CVE-2005-0996 | Media (5) | 1.0% | — | 2 may 2005 | Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the email or url parameters in the Add function, (2) the min… |
| CVE-2005-1180 | Media (5) | 1.4% | — | 2 may 2005 | HTTP Response Splitting vulnerability in the Surveys module in PHP-Nuke 7.6 allows remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the forwarder parameter. |
| CVE-2005-0999 | Alta (7.5) | 3.8% | — | 2 may 2005 | SQL injection vulnerability in the Top module for PHP-Nuke 6.x through 7.6 allows remote attackers to execute arbitrary SQL commands via the querylang parameter. |
| CVE-2005-0998 | Media (5) | 1.2% | — | 2 may 2005 | The Web_Links module for PHP-Nuke 7.6 allows remote attackers to obtain sensitive information via an invalid show parameter, which triggers a division by zero PHP error that leaks the full pathname of the server. |
| CVE-2005-1024 | Media (5) | 1.7% | — | 2 may 2005 | modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) my_headlines, (2) userinfo, or (3) search, which reveals the path in a PHP error message. |
| CVE-2005-1001 | Media (5) | 1.5% | — | 2 may 2005 | PHP-Nuke 7.6 allows remote attackers to obtain sensitive information via direct requests to (1) the Surveys module with the file parameter set to comments or (2) 3D-Fantasy/theme.php, which leaks the full pathname of… |
| CVE-2005-1023 | Media (4.3) | 1.7% | — | 2 may 2005 | Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) min parameter to the Search module, (2) the categories parameter to… |
| CVE-2005-1027 | Media (4.3) | 1.7% | — | 2 may 2005 | Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x through 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in the Your_Account module, (2) avatarcategory… |