Page 4 of 71 results (0.009 seconds)

CVSS: 10.0EPSS: 0%CPEs: 15EXPL: 0

Multiple unspecified vulnerabilities in the WYSIWYG editor in PHP-Nuke before 7.9 Final have unknown impact and attack vectors. • http://secunia.com/advisories/16843 http://www.phpnuke.org/modules.php?name=News&file=article&sid=7435 •

CVSS: 5.0EPSS: 0%CPEs: 18EXPL: 0

PHP-Nuke 7.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) ipban.php, (2) db.php, (3) lang-norwegian.php, (4) lang-indonesian.php, (5) lang-greek.php, (6) a request to Web_Links with the portuguese language (lang-portuguese.php), (7) a request to Web_Links with the indonesian language (lang-indonesian.php), (8) a request to the survey module with the indonesian language (lang-indonesian.php), (9) a request to the Reviews module with the portuguese language, or (10) a request to the Journal module with the portuguese language, which reveal the path in an error message. • http://marc.info/?l=bugtraq&m=111478982629035&w=2 •

CVSS: 5.0EPSS: 0%CPEs: 2EXPL: 1

HTTP Response Splitting vulnerability in the Surveys module in PHP-Nuke 7.6 allows remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the forwarder parameter. • http://marc.info/?l=bugtraq&m=111359804013536&w=2 http://secunia.com/advisories/14965 http://www.digitalparadox.org/advisories/pnuke.txt http://www.osvdb.org/15647 https://exchange.xforce.ibmcloud.com/vulnerabilities/20116 •

CVSS: 5.0EPSS: 0%CPEs: 18EXPL: 1

modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) my_headlines, (2) userinfo, or (3) search, which reveals the path in a PHP error message. • http://marc.info/?l=bugtraq&m=111263454308478&w=2 http://www.securityreason.com/adv/PHPNuke%206.x-7.6-p1.txt https://exchange.xforce.ibmcloud.com/vulnerabilities/19953 https://exchange.xforce.ibmcloud.com/vulnerabilities/44980 •

CVSS: 4.3EPSS: 0%CPEs: 18EXPL: 1

Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) min parameter to the Search module, (2) the categories parameter to the FAQ module, or (3) the ltr parameter to the Encyclopedia module. NOTE: the bid parameter issue in banners.php is already an item in CVE-2005-1000. • https://www.exploit-db.com/exploits/24190 http://marc.info/?l=bugtraq&m=111263454308478&w=2 http://www.securityreason.com/adv/PHPNuke%206.x-7.6-p1.txt https://exchange.xforce.ibmcloud.com/vulnerabilities/19952 •