Vulnerabilities > Francisco Burzi > PHP Nuke > 6.5.final

DATE CVE VULNERABILITY TITLE RISK
2006-02-21 CVE-2006-0805 Unspecified vulnerability in Francisco Burzi PHP-Nuke
The CAPTCHA functionality in php-Nuke 6.0 through 7.9 uses fixed challenge/response pairs that only vary once per day based on the User Agent (HTTP_USER_AGENT), which allows remote attackers to bypass CAPTCHA controls by fixing the User Agent, performing a valid challenge/response, then replaying that pair in the random_num and gfx_check parameters.
network
low complexity
francisco-burzi
7.5
2006-02-13 CVE-2006-0676 Cross-Site Scripting vulnerability in PHPNuke
Cross-site scripting (XSS) vulnerability in header.php in PHP-Nuke 6.0 to 7.8 allows remote attackers to inject arbitrary web script or HTML via the pagetitle parameter.
network
francisco-burzi
4.3
2005-05-03 CVE-2005-1386 Information Disclosure vulnerability in PHP-Nuke
PHP-Nuke 7.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) ipban.php, (2) db.php, (3) lang-norwegian.php, (4) lang-indonesian.php, (5) lang-greek.php, (6) a request to Web_Links with the portuguese language (lang-portuguese.php), (7) a request to Web_Links with the indonesian language (lang-indonesian.php), (8) a request to the survey module with the indonesian language (lang-indonesian.php), (9) a request to the Reviews module with the portuguese language, or (10) a request to the Journal module with the portuguese language, which reveal the path in an error message.
network
low complexity
francisco-burzi
5.0
2005-05-02 CVE-2005-1027 Cross-Site Scripting vulnerability in PHP-Nuke Modules.PHP Username URI Parameter
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x through 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in the Your_Account module, (2) avatarcategory parameter in the Your_Account module, or (3) lid parameter in the Downloads module.
network
francisco-burzi
4.3
2005-05-02 CVE-2005-1024 Unspecified vulnerability in Francisco Burzi PHP-Nuke
modules.php in PHP-Nuke 6.x to 7.6 allows remote attackers to obtain sensitive information via a direct request to (1) my_headlines, (2) userinfo, or (3) search, which reveals the path in a PHP error message.
network
low complexity
francisco-burzi
5.0
2005-05-02 CVE-2005-1023 Unspecified vulnerability in Francisco Burzi PHP-Nuke
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) min parameter to the Search module, (2) the categories parameter to the FAQ module, or (3) the ltr parameter to the Encyclopedia module.
network
francisco-burzi
4.3
2005-05-02 CVE-2005-0999 Unspecified vulnerability in Francisco Burzi PHP-Nuke
SQL injection vulnerability in the Top module for PHP-Nuke 6.x through 7.6 allows remote attackers to execute arbitrary SQL commands via the querylang parameter.
network
low complexity
francisco-burzi
7.5
2005-02-15 CVE-2005-0434 Cross-Site Scripting vulnerability in PHP-Nuke
Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 7.5 allow remote attackers to inject arbitrary HTML or web script via (1) the newdownloadshowdays parameter in a NewDownloads operation or (2) the newlinkshowdays parameter in a NewLinks operation.
network
francisco-burzi
4.3
2005-02-15 CVE-2005-0433 Cross-Site Scripting vulnerability in PHP-Nuke
Php-Nuke 7.5 allows remote attackers to determine the full path of the web server via invalid or missing arguments to (1) db.php, (2) mainfile.php, (3) Downloads/index.php, or (4) Web_Links/index.php, which lists the path in a PHP error message.
network
low complexity
francisco-burzi
5.0
2004-12-31 CVE-2004-2354 Cross-Site Scripting vulnerability in 4Nguestbook
SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-site scripting (XSS) attacks when MySQL errors are triggered.
6.8