Vulnerabilities > Francisco Burzi > PHP Nuke > 6.9

DATE CVE VULNERABILITY TITLE RISK
2004-04-30 CVE-2004-1985 Input Validation vulnerability in Coppermine Photo Gallery
Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web script via the CPG_URL parameter.
4.3
2004-04-13 CVE-2004-1929 SQL Injection vulnerability in PHP-Nuke
SQL injection vulnerability in the bblogin function in functions.php in PHP-Nuke 6.x through 7.2 allows remote attackers to bypass authentication and gain access by injecting base64-encoded SQL code into the user parameter.
network
low complexity
francisco-burzi
7.5
2004-04-12 CVE-2004-1932 SQL-Injection vulnerability in PHP-Nuke
SQL injection vulnerability in (1) auth.php and (2) admin.php in PHP-Nuke 6.x through 7.2 allows remote attackers to execute arbitrary SQL code and create an administrator account via base64-encoded SQL in the admin parameter.
network
low complexity
francisco-burzi
7.5
2004-04-12 CVE-2004-1930 Cross-Site Scripting vulnerability in PHP-Nuke CookieDecode
Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie.
network
francisco-burzi
4.3
2004-04-04 CVE-2004-1986 Input Validation vulnerability in Coppermine Photo Gallery
Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to read arbitrary files via a ..
network
low complexity
coppermine francisco-burzi
5.0
2004-03-22 CVE-2004-1840 Cross-Site Scripting vulnerability in PHP-Nuke MS-Analysis Module
Multiple cross-site scripting (XSS) vulnerabilities in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) screen parameter to modules.php, (2) module_name parameter to title.php, (3) sortby parameter to modules.php, or (4) overview parameter to modules.php.
network
francisco-burzi
4.3
2004-03-22 CVE-2004-1839 Remote Path Disclosure vulnerability in PHP-Nuke MS-Analysis Module
MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) browsers.php, (2) mstrack.php, or (3) title.php, which reveal the full path in a PHP error message.
network
low complexity
francisco-burzi
5.0