Php Nuke

Vendor:

First CVE: Oct 20, 2000 · Active for 25 years

94
Total CVEs
More Total CVEs than 99% of tracked products
10.4
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Php Nuke over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 20, 2000
25 years ago
Most Recent CVE
Jan 25, 2008
6,759 days ago

CVE Severity & Scoring

Php Nuke94 CVEs
All CVEs353,173 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown94 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown94 (100.0%)
User Interaction
None0 (0.0%)
Unknown94 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown94 (100.0%)

Top CVEs

Signals from CVEs in this product scope (94 CVEs).

94 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" block is enabled, allows remote attackers to execute arbitrary
Feb 22, 20076.860NOYES
Multiple SQL injection vulnerabilities in the Search module in PHP-Nuke 7.8, and possibly other versions before 7.9 with patch 3.1, allows remote attackers to execute arbitrary SQL
Nov 24, 20057.552NOYES
PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP f
Jun 1, 20047.539NOYES
PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by modifying the CPG_M_DIR to re
Apr 30, 20047.539NOYES
PHP remote file inclusion vulnerability in index.php in Php-Nuke 6.x through 7.3 allows remote attackers to execute arbitrary PHP code by modifying the modpath parameter to referen
Dec 31, 20047.537NOYES
Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 5.x through 6.5 allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to th
Dec 31, 20037.536NOYES
SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category
Nov 23, 20046.435NOYES
SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL commands via the eid parameter.
Dec 31, 20047.534NOYES
Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) f
Nov 23, 20046.834NOYES
SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the days parameter to the search module.
Dec 31, 20037.534NOYES

Exploit Exposure

Signals from CVEs in this product scope (94 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
48 CVEs
51.1% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (94 CVEs).

Media Mentions

Signals from CVEs in this product scope (94 CVEs).

Top CNAs Publishing CVEs For Php Nuke

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.0_final116.22.0%04
7.956.22.9%03
7.8_patched_3.227.52.6%00
7.8116.66.4%06
7.776.98.3%05
7.6205.84.0%010
7.596.52.3%05
7.496.52.3%05
7.3225.84.5%013
7.2345.94.7%021
7.1365.84.6%023
7.0_final315.75.0%019
7.0375.73.3%021
6.9355.73.5%020
6.836.41.4%00
6.7295.62.7%016
6.6295.62.7%016
6.5_rc3295.52.9%018
6.5_rc2295.52.9%018
6.5_rc1295.52.9%018