Vulnerabilities (CVE)

Filtered by vendor Nukebookmarks Subscribe
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-0900 1 Nukebookmarks 1 Nukebookmarks 2024-02-04 5.0 MEDIUM N/A
marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to obtain sensitive information via an invalid (1) file or (2) category parameter, which reveal the path in an error message.
CVE-2005-0901 1 Nukebookmarks 1 Nukebookmarks 2024-02-04 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in NukeBookmarks 0.6 for PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via the (1) catname, (2) markname, (3) comment, or (4) category parameter.
CVE-2005-0902 1 Nukebookmarks 1 Nukebookmarks 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category parameter.