CVE-2005-1023 – PHP-Nuke 6.x/7.x FAQ Module - 'categories' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2005-1023
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) min parameter to the Search module, (2) the categories parameter to the FAQ module, or (3) the ltr parameter to the Encyclopedia module. NOTE: the bid parameter issue in banners.php is already an item in CVE-2005-1000. • https://www.exploit-db.com/exploits/24190 http://marc.info/?l=bugtraq&m=111263454308478&w=2 http://www.securityreason.com/adv/PHPNuke%206.x-7.6-p1.txt https://exchange.xforce.ibmcloud.com/vulnerabilities/19952 •
CVE-2005-1024
https://notcve.org/view.php?id=CVE-2005-1024
modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) my_headlines, (2) userinfo, or (3) search, which reveals the path in a PHP error message. • http://marc.info/?l=bugtraq&m=111263454308478&w=2 http://www.securityreason.com/adv/PHPNuke%206.x-7.6-p1.txt https://exchange.xforce.ibmcloud.com/vulnerabilities/19953 https://exchange.xforce.ibmcloud.com/vulnerabilities/44980 •
CVE-2005-1001
https://notcve.org/view.php?id=CVE-2005-1001
PHP-Nuke 7.6 allows remote attackers to obtain sensitive information via direct requests to (1) the Surveys module with the file parameter set to comments or (2) 3D-Fantasy/theme.php, which leaks the full pathname of the web server in a PHP error message. • http://archives.neohapsis.com/archives/bugtraq/2005-04/0037.html https://exchange.xforce.ibmcloud.com/vulnerabilities/19953 •
CVE-2005-0999 – PHP-Nuke 6.x < 7.6 Top module - SQL Injection
https://notcve.org/view.php?id=CVE-2005-0999
SQL injection vulnerability in the Top module for PHP-Nuke 6.x through 7.6 allows remote attackers to execute arbitrary SQL commands via the querylang parameter. • https://www.exploit-db.com/exploits/921 http://marc.info/?l=bugtraq&m=111281649616901&w=2 http://www.waraxe.us/advisory-41.html •
CVE-2005-1000 – PHP-Nuke 6.x/7.x Your_Account Module - 'Username' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2005-1000
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the bid parameter to the EmailStats op in banners.pgp, (2) the ratenum parameter in the TopRated and MostPopular actions in the Web_Links module, (3) the ttitle parameter in the viewlinkdetails, viewlinkeditorial, viewlinkcomments, and ratelink actions in the Web_Links module, or (4) the username parameter in the Your_Account module. • https://www.exploit-db.com/exploits/25339 https://www.exploit-db.com/exploits/25340 https://www.exploit-db.com/exploits/25343 https://www.exploit-db.com/exploits/25342 http://archives.neohapsis.com/archives/bugtraq/2005-04/0037.html http://marc.info/?l=bugtraq&m=111263454308478&w=2 https://exchange.xforce.ibmcloud.com/vulnerabilities/19952 •