Page 5 of 42 results (0.001 seconds)

CVSS: 7.5EPSS: 4%CPEs: 2EXPL: 1

31 Dec 2003 — Absolute path traversal vulnerability in nukestyles.com viewpage.php addon for PHP-Nuke allows remote attackers to read arbitrary files via a full pathname in the file parameter. NOTE: This was originally reported as an issue in PHP-Nuke 6.5, but this is an independent addon. • https://www.exploit-db.com/exploits/22422 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 9.8EPSS: 4%CPEs: 2EXPL: 1

16 Nov 2001 — Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variable. • https://www.exploit-db.com/exploits/21155 •