Vulnerabilities > Francisco Burzi > PHP Nuke > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2004-07-27 | CVE-2004-0731 | Unspecified vulnerability in Francisco Burzi PHP-Nuke 8.0Final Cross-site scripting (XSS) vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary script as other users via the input field. network francisco-burzi | 6.8 |
2004-05-05 | CVE-2004-1999 | Cross-Site Scripting vulnerability in PHP-Nuke Cross-site scripting (XSS) vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to inject arbitrary HTML and web script via the (1) ttitle or (2) sid parameters to modules.php. network francisco-burzi | 4.3 |
2004-05-05 | CVE-2004-1998 | Information Disclosure vulnerability in PHP-Nuke The Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to gain sensitive information via an invalid show parameter to modules.php, which reveals the full path in a PHP error message. | 5.0 |
2004-05-02 | CVE-2004-1984 | Information Disclosure vulnerability in Coppermine Photo Gallery Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) phpinfo.php, (2) addpic.php, (3) config.php, (4) db_input.php, (5) displayecard.php, (6) ecard.php, (7) crop.inc.php, which reveal the full path in a PHP error message. | 5.0 |
2004-04-30 | CVE-2004-1985 | Input Validation vulnerability in Coppermine Photo Gallery Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web script via the CPG_URL parameter. | 4.3 |
2004-04-12 | CVE-2004-1930 | Cross-Site Scripting vulnerability in PHP-Nuke CookieDecode Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie. network francisco-burzi | 4.3 |
2004-04-04 | CVE-2004-1986 | Input Validation vulnerability in Coppermine Photo Gallery Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to read arbitrary files via a .. | 5.0 |
2004-03-22 | CVE-2004-1840 | Cross-Site Scripting vulnerability in PHP-Nuke MS-Analysis Module Multiple cross-site scripting (XSS) vulnerabilities in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) screen parameter to modules.php, (2) module_name parameter to title.php, (3) sortby parameter to modules.php, or (4) overview parameter to modules.php. network francisco-burzi | 4.3 |
2004-03-22 | CVE-2004-1839 | Remote Path Disclosure vulnerability in PHP-Nuke MS-Analysis Module MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) browsers.php, (2) mstrack.php, or (3) title.php, which reveal the full path in a PHP error message. | 5.0 |
2004-03-18 | CVE-2004-1830 | Multiple vulnerability in Francisco Burzi PHP-Nuke 6.0 error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (3) lang parameter, which leaks the pathname in a PHP error message. | 5.0 |