Vulnerabilities > Francisco Burzi > PHP Nuke > Critical

DATE CVE VULNERABILITY TITLE RISK
2005-09-21 CVE-2005-3016 Remote Security vulnerability in PHP-Nuke
Multiple unspecified vulnerabilities in the WYSIWYG editor in PHP-Nuke before 7.9 Final have unknown impact and attack vectors.
network
low complexity
francisco-burzi
critical
10.0
2001-08-31 CVE-2001-1025 Remote SQL Query Manipulation vulnerability in PHP-Nuke 5.0/5.0.1
PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php.
network
low complexity
francisco-burzi
critical
10.0
2001-05-03 CVE-2001-0320 Remote Security vulnerability in PHP-Nuke 4.0.4/4.4
bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and ..
network
low complexity
francisco-burzi
critical
10.0