Vulnerabilities > Francisco Burzi > Medium

DATE CVE VULNERABILITY TITLE RISK
2004-07-27 CVE-2004-0731 Unspecified vulnerability in Francisco Burzi PHP-Nuke 8.0Final
Cross-site scripting (XSS) vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary script as other users via the input field.
network
francisco-burzi
6.8
2004-05-05 CVE-2004-1999 Cross-Site Scripting vulnerability in PHP-Nuke
Cross-site scripting (XSS) vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to inject arbitrary HTML and web script via the (1) ttitle or (2) sid parameters to modules.php.
network
francisco-burzi
4.3
2004-05-05 CVE-2004-1998 Information Disclosure vulnerability in PHP-Nuke
The Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to gain sensitive information via an invalid show parameter to modules.php, which reveals the full path in a PHP error message.
network
low complexity
francisco-burzi
5.0
2004-05-02 CVE-2004-1984 Information Disclosure vulnerability in Coppermine Photo Gallery
Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) phpinfo.php, (2) addpic.php, (3) config.php, (4) db_input.php, (5) displayecard.php, (6) ecard.php, (7) crop.inc.php, which reveal the full path in a PHP error message.
network
low complexity
coppermine francisco-burzi
5.0
2004-04-30 CVE-2004-1985 Input Validation vulnerability in Coppermine Photo Gallery
Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web script via the CPG_URL parameter.
4.3
2004-04-12 CVE-2004-1930 Cross-Site Scripting vulnerability in PHP-Nuke CookieDecode
Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie.
network
francisco-burzi
4.3
2004-04-04 CVE-2004-1986 Input Validation vulnerability in Coppermine Photo Gallery
Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to read arbitrary files via a ..
network
low complexity
coppermine francisco-burzi
5.0
2004-03-22 CVE-2004-1840 Cross-Site Scripting vulnerability in PHP-Nuke MS-Analysis Module
Multiple cross-site scripting (XSS) vulnerabilities in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) screen parameter to modules.php, (2) module_name parameter to title.php, (3) sortby parameter to modules.php, or (4) overview parameter to modules.php.
network
francisco-burzi
4.3
2004-03-22 CVE-2004-1839 Remote Path Disclosure vulnerability in PHP-Nuke MS-Analysis Module
MS Analysis module 2.0 for PHP-Nuke allows remote attackers to obtain sensitive information via a direct request to (1) browsers.php, (2) mstrack.php, or (3) title.php, which reveal the full path in a PHP error message.
network
low complexity
francisco-burzi
5.0
2004-03-18 CVE-2004-1830 Multiple vulnerability in Francisco Burzi PHP-Nuke 6.0
error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (1) language, (2) newlang, or (3) lang parameter, which leaks the pathname in a PHP error message.
network
low complexity
francisco-burzi
5.0