NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 69858 | CVE-2005-4260 | Interpretation conflict in includes/mainfile.php in PHP-Nuke 7.9 and later allows remote attackers to perform cross-site scripting (XSS) attacks by replacing the ">" in the tag with a "<", which bypasses the regular expressions that sanitize the data, but is automatically corrected by many web browsers. NOTE: it could be argued that this vulnerability is due to a design limitation of many web browsers; if so, then this should not be treated as a vulnerability in PHP-Nuke. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
| 4578 | CVE-2008-4764 | Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter in a show_error action. | 2 | 5 | Medium | 2017-01-03 | 2012-07-13 | View | |
| 70114 | CVE-2005-4516 | Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion 6.00.200 through 6.00.300 allow remote attackers to inject arbitrary web script or HTML via (1) the sortby parameter in members.php and (2) IMG tags. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
| 4834 | CVE-2008-5047 | SQL injection vulnerability in admin/index.php in Mole Group Rental Script allows remote attackers to execute arbitrary SQL commands via the username parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-03-13 | View | |
| 70370 | CVE-2005-4781 | Multiple SQL injection vulnerabilities in SergiDs Top Music module 3.0 PR3 and earlier for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the (1) idartist, (2) idsong, and (3) idalbum parameters to modules.php. | 2 | 5 | Medium | 2017-01-03 | 2008-09-20 | View |
Page 15289 of 17672, showing 5 records out of 88360 total, starting on record 76441, ending on 76445