
CVE-2005-0996
https://notcve.org/view.php?id=CVE-2005-0996
07 Apr 2005 — Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the email or url parameters in the Add function, (2) the min parameter in the viewsdownload function, or (3) the min parameter in the search function. • http://marc.info/?l=bugtraq&m=111289685724764&w=2 •

CVE-2005-0997 – PHP-Nuke 7.6 Web_Links Module - Multiple SQL Injections
https://notcve.org/view.php?id=CVE-2005-0997
07 Apr 2005 — Multiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 7.6 allow remote attackers to execute arbitrary SQL commands via (1) the email or url parameters in the Add function, (2) the url parameter in the modifylinkrequestS function, (3) the orderby or min parameters in the viewlink function, (4) the orderby, min, or show parameters in the search function, or (5) the ratenum parameter in the MostPopular function. • https://www.exploit-db.com/exploits/25360 •

CVE-2005-0999 – PHP-Nuke 6.x < 7.6 Top module - SQL Injection
https://notcve.org/view.php?id=CVE-2005-0999
07 Apr 2005 — SQL injection vulnerability in the Top module for PHP-Nuke 6.x through 7.6 allows remote attackers to execute arbitrary SQL commands via the querylang parameter. • https://www.exploit-db.com/exploits/921 •

CVE-2005-1000 – PHP-Nuke 7.6 - 'banners.php' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2005-1000
07 Apr 2005 — Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the bid parameter to the EmailStats op in banners.pgp, (2) the ratenum parameter in the TopRated and MostPopular actions in the Web_Links module, (3) the ttitle parameter in the viewlinkdetails, viewlinkeditorial, viewlinkcomments, and ratelink actions in the Web_Links module, or (4) the username parameter in the Your_Account module. • https://www.exploit-db.com/exploits/25343 •

CVE-2005-0434
https://notcve.org/view.php?id=CVE-2005-0434
15 Feb 2005 — Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 7.5 allow remote attackers to inject arbitrary HTML or web script via (1) the newdownloadshowdays parameter in a NewDownloads operation or (2) the newlinkshowdays parameter in a NewLinks operation. • http://www.securityfocus.com/bid/12561 •

CVE-2005-0433
https://notcve.org/view.php?id=CVE-2005-0433
15 Feb 2005 — Php-Nuke 7.5 allows remote attackers to determine the full path of the web server via invalid or missing arguments to (1) db.php, (2) mainfile.php, (3) Downloads/index.php, or (4) Web_Links/index.php, which lists the path in a PHP error message. • http://www.securityfocus.com/bid/12561 •