CVE-2001-1032
https://notcve.org/view.php?id=CVE-2001-1032
admin.php in PHP-Nuke 5.2 and earlier, except 5.0RC1, does not check login credentials for upload operations, which allows remote attackers to copy and upload arbitrary files and read the PHP-Nuke configuration file by directly calling admin.php with an upload parameter and specifying the file to copy. • http://archives.neohapsis.com/archives/bugtraq/2001-09/0203.html http://sourceforge.net/forum/forum.php?forum_id=113892 http://www.securityfocus.com/bid/3361 https://exchange.xforce.ibmcloud.com/vulnerabilities/7170 •
CVE-2001-0383 – PHP-Nuke 1.0/2.5/3.0/4.x - Remote Ad Banner URL Change
https://notcve.org/view.php?id=CVE-2001-0383
banners.php in PHP-Nuke 4.4 and earlier allows remote attackers to modify banner ad URLs by directly calling the Change operation, which does not require authentication. • https://www.exploit-db.com/exploits/20729 http://archives.neohapsis.com/archives/bugtraq/2001-04/0017.html http://phpnuke.org/download.php?dcategory=Fixes http://www.securityfocus.com/bid/2544 https://exchange.xforce.ibmcloud.com/vulnerabilities/6342 •
CVE-2001-0001
https://notcve.org/view.php?id=CVE-2001-0001
cookiedecode function in PHP-Nuke 4.4 allows users to bypass authentication and gain access to other user accounts by extracting the authentication information from a cookie. • http://archives.neohapsis.com/archives/bugtraq/2001-02/0257.html https://exchange.xforce.ibmcloud.com/vulnerabilities/6183 •
CVE-2001-0320
https://notcve.org/view.php?id=CVE-2001-0320
bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument. • http://archives.neohapsis.com/archives/bugtraq/2001-02/0425.html •
CVE-2000-0745 – PHP-Nuke 1.0/2.5 - Administrative Privileges
https://notcve.org/view.php?id=CVE-2000-0745
admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter. • https://www.exploit-db.com/exploits/20158 http://archives.neohapsis.com/archives/bugtraq/2000-08/0243.html http://www.osvdb.org/1521 http://www.securityfocus.com/bid/1592 •