CVE-2001-0383 – PHP-Nuke 1.0/2.5/3.0/4.x - Remote Ad Banner URL Change
https://notcve.org/view.php?id=CVE-2001-0383
banners.php in PHP-Nuke 4.4 and earlier allows remote attackers to modify banner ad URLs by directly calling the Change operation, which does not require authentication. • https://www.exploit-db.com/exploits/20729 http://archives.neohapsis.com/archives/bugtraq/2001-04/0017.html http://phpnuke.org/download.php?dcategory=Fixes http://www.securityfocus.com/bid/2544 https://exchange.xforce.ibmcloud.com/vulnerabilities/6342 •
CVE-2000-0745 – PHP-Nuke 1.0/2.5 - Administrative Privileges
https://notcve.org/view.php?id=CVE-2000-0745
admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter. • https://www.exploit-db.com/exploits/20158 http://archives.neohapsis.com/archives/bugtraq/2000-08/0243.html http://www.osvdb.org/1521 http://www.securityfocus.com/bid/1592 •