Nuked Klan is a narrowly scoped vendor centered on a small set of products including its core platform and a partners module. The durable signal from its vulnerability footprint is limited to the defined product scope itself, with no distinct recurrent weakness-class pattern emerging. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nuked Klan over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4925HIGH SQL injection vulnerability in clic.php in the Partenaires module 1.5 for Nuked-Klan allows remote attackers to execute arbitrary SQL commands via the id parameter. | Oct 9, 2011 | 7.5 | 31 | NO | YES |
CVE-2007-2556HIGH SQL injection vulnerability in Nuked-klaN 1.7.6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For (X_FORWARDED_FOR) HTTP header, as demonstrated by | May 9, 2007 | 7.5 | 29 | NO | YES |
CVE-2005-3305HIGH Multiple SQL injection vulnerabilities in Nuked Klan 1.7 allow remote attackers to execute arbitrary SQL commands via the (1) forum_id or (2) thread_id parameter in the Forum file, | Oct 26, 2005 | 7.5 | 28 | NO | YES |
CVE-2003-1371MEDIUM Nuked-Klan 1.3b, and possibly earlier versions, allows remote attackers to obtain sensitive server information via an op parameter set to phpinfo for the (1) Team, (2) News, or (3) | Dec 31, 2003 | 4.3 | 27 | NO | YES |
CVE-2004-1937MEDIUM Multiple directory traversal vulnerabilities in Nuked-KlaN 1.4b and 1.5b allow remote attackers to read or include arbitrary files via .. sequences in (1) the user_langue parameter | Dec 31, 2004 | 5.0 | 25 | NO | YES |
CVE-2006-1419MEDIUM SQL injection vulnerability in the Calendar module in nuked-klan 1.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter to index.php. | Mar 28, 2006 | 5.0 | 22 | NO | YES |
CVE-2003-1238MEDIUM Cross-site scripting vulnerability (XSS) in Nuked-Klan 1.3 beta and earlier allows remote attackers to steal authentication information via cookies by injecting arbitrary HTML or s | Dec 31, 2003 | 5.8 | 21 | NO | NO |
CVE-2007-0083MEDIUM Cross-site scripting (XSS) vulnerability in Nuked Klan 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a getURL statement in | Jan 5, 2007 | 6.8 | 18 | NO | NO |
CVE-2008-7132MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Nuked-Klan 1.3 beta allows remote attackers to inject arbitrary web script or HTML via the nuked_nude parameter. NOTE: the | Sep 1, 2009 | 4.3 | 15 | NO | NO |
CVE-2006-3479MEDIUM Cross-site request forgery (CSRF) vulnerability in the del_block function in modules/Admin/block.php in Nuked-Klan 1.7.5 and earlier and 1.7 SP4.2 allows remote attackers to delete | Jul 10, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nuked Klan.
Media articles that mention a CVE ID that affects a product developed by Nuked Klan — matched by CVE ID, not by vendor name.