Vulnerabilities
Vulnerable Software
Francisco Burzi:  >> Php-Nuke  Security Vulnerabilities
banners.php in PHP-Nuke 4.4 and earlier allows remote attackers to modify banner ad URLs by directly calling the Change operation, which does not require authentication.
CVSS Score
5.0
EPSS Score
0.001
Published
2001-06-18
cookiedecode function in PHP-Nuke 4.4 allows users to bypass authentication and gain access to other user accounts by extracting the authentication information from a cookie.
CVSS Score
7.5
EPSS Score
0.0
Published
2001-06-02
PHP-Nuke 4.4.1a allows remote attackers to modify a user's email address and obtain the password by guessing the user id (UID) and calling user.php with the saveuser operator.
CVSS Score
7.5
EPSS Score
0.0
Published
2001-05-03
bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument.
CVSS Score
10.0
EPSS Score
0.001
Published
2001-05-03
opendir.php script in PHP-Nuke allows remote attackers to read arbitrary files by specifying the filename as an argument to the requesturl parameter.
CVSS Score
5.0
EPSS Score
0.001
Published
2001-05-03
admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter.
CVSS Score
7.5
EPSS Score
0.001
Published
2000-10-20


Contact Us

Shodan ® - All rights reserved