Page 3 of 99 results (0.004 seconds)

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

SQL injection vulnerability in the Your_Account module in PHP-Nuke 7.8 might allows remote attackers to execute arbitrary SQL commands via the user_id parameter in the Your_Home functionality. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. • http://secunia.com/advisories/18972 http://www.osvdb.org/23432 http://www.securityfocus.com/bid/16774 http://www.vupen.com/english/advisories/2006/0687 https://exchange.xforce.ibmcloud.com/vulnerabilities/44730 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 1

SQL injection vulnerability in PHP-Nuke before 7.8 Patched 3.2 allows remote attackers to execute arbitrary SQL commands via encoded /%2a (/*) sequences in the query string, which bypasses regular expressions that are intended to protect against SQL injection, as demonstrated via the kala parameter. • http://www.securityfocus.com/archive/1/426083/100/0/threaded http://www.waraxe.us/advisory-47.html •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 1

PHP-Nuke 7.8 Patched 3.2 allows remote attackers to bypass SQL injection protection mechanisms via /%2a (/*) sequences with the "ad_click" word in the query string, as demonstrated via the kala parameter. • http://securityreason.com/securityalert/497 http://www.securityfocus.com/archive/1/426083/100/0/threaded http://www.waraxe.us/advisory-47.html •

CVSS: 7.5EPSS: 2%CPEs: 21EXPL: 3

The CAPTCHA functionality in php-Nuke 6.0 through 7.9 uses fixed challenge/response pairs that only vary once per day based on the User Agent (HTTP_USER_AGENT), which allows remote attackers to bypass CAPTCHA controls by fixing the User Agent, performing a valid challenge/response, then replaying that pair in the random_num and gfx_check parameters. • https://www.exploit-db.com/exploits/27249 http://secunia.com/advisories/18936 http://securityreason.com/securityalert/455 http://www.securityfocus.com/archive/1/425394/100/0/threaded http://www.securityfocus.com/bid/16722 http://www.waraxe.us/advisory-45.html •

CVSS: 7.5EPSS: 7%CPEs: 1EXPL: 2

SQL injection vulnerability in index.php in the Your_Account module in PHP-Nuke 7.8 and earlier allows remote attackers to execute arbitrary SQL commands via the username variable (Nickname field). • http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0358.html http://secunia.com/advisories/18931 http://securityreason.com/achievement_securityalert/32 http://securityreason.com/securityalert/440 http://www.osvdb.org/23259 http://www.securityfocus.com/archive/1/425173/100/0/threaded http://www.securityfocus.com/bid/16691 http://www.vupen.com/english/advisories/2006/0636 https://exchange.xforce.ibmcloud.com/vulnerabilities/24769 •