CVE-2005-1024
https://notcve.org/view.php?id=CVE-2005-1024
modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) my_headlines, (2) userinfo, or (3) search, which reveals the path in a PHP error message. • http://marc.info/?l=bugtraq&m=111263454308478&w=2 http://www.securityreason.com/adv/PHPNuke%206.x-7.6-p1.txt https://exchange.xforce.ibmcloud.com/vulnerabilities/19953 https://exchange.xforce.ibmcloud.com/vulnerabilities/44980 •
CVE-2005-1023 – PHP-Nuke 6.x/7.x FAQ Module - 'categories' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2005-1023
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) min parameter to the Search module, (2) the categories parameter to the FAQ module, or (3) the ltr parameter to the Encyclopedia module. NOTE: the bid parameter issue in banners.php is already an item in CVE-2005-1000. • https://www.exploit-db.com/exploits/24190 http://marc.info/?l=bugtraq&m=111263454308478&w=2 http://www.securityreason.com/adv/PHPNuke%206.x-7.6-p1.txt https://exchange.xforce.ibmcloud.com/vulnerabilities/19952 •
CVE-2005-1028
https://notcve.org/view.php?id=CVE-2005-1028
PHP-Nuke 6.x through 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) index.php with the forum_admin parameter set, (2) the Surveys module, or (3) the Your_Account module, which reveals the path in a PHP error message. PHP-Nuke 6.x hasta la versión 7.6 permite a atacantes remotos obtener información sensible a través de una petición directa a (1) index.php con el parámetro forum_admin establecido, (2) el módulo Surveys o (3) el módulo Your_Account, lo que revela la ruta en un mensaje de error PHP. • http://marc.info/?l=bugtraq&m=111272010303144&w=2 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2005-1027 – PHP-Nuke 6.x/7.x 'Downloads' Module - 'Lid' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2005-1027
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x through 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in the Your_Account module, (2) avatarcategory parameter in the Your_Account module, or (3) lid parameter in the Downloads module. • https://www.exploit-db.com/exploits/25341 http://marc.info/?l=bugtraq&m=111272010303144&w=2 http://www.securityfocus.com/archive/1/321324 http://www.securityfocus.com/bid/7570 https://exchange.xforce.ibmcloud.com/vulnerabilities/11994 •
CVE-2005-0999 – PHP-Nuke 6.x < 7.6 Top module - SQL Injection
https://notcve.org/view.php?id=CVE-2005-0999
SQL injection vulnerability in the Top module for PHP-Nuke 6.x through 7.6 allows remote attackers to execute arbitrary SQL commands via the querylang parameter. • https://www.exploit-db.com/exploits/921 http://marc.info/?l=bugtraq&m=111281649616901&w=2 http://www.waraxe.us/advisory-41.html •