Vulnerabilities
30 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-46887 | Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takecon Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takeconfirm.php; the delcheater parameter in cheaterbox.php; or the usernw parameter in nowarn.php. NVD description · AI analysis pending | 9.8 group max | 19% | PoC |
| — | |
| CVE-2020-24770 | SQL injection vulnerability in modrules.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. SQL injection vulnerability in modrules.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — | |
| CVE-2017-15305 | XSS exists in NexusPHP 1.5 via the keyword parameter to messages.php. XSS exists in NexusPHP 1.5 via the keyword parameter to messages.php. NVD description · AI analysis pending | 6.1 | <1% | PoC ×2 |
| — | |
| CVE-2017-12792 | Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authentication of administrators for requests th Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) linkname, (2) url, or (3) title parameter in an add action to linksmanage.php. NVD description · AI analysis pending | 6.1 | 1% | PoC |
| — | |
| CVE-2017-14534 | Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF. Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2017-14512 | NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different vulnerability than CVE-2017-12981. NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different vulnerability than CVE-2017-12981. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2017-14347 | NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to fun.php in a delete action. NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to fun.php in a delete action. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2017-12838 +1 in the same advisory: …12906 | Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests that (1) send manas v Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests that (1) send manas via a request to mybonus.php or (2) add administrators via unspecified vectors. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2017-14069 | SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the usernw array parameter to nowarn.php. SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the usernw array parameter to nowarn.php. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2017-13669 +1 in the same advisory: …12679 | SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswered parameter to staffbox.php. SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswered parameter to staffbox.php. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2017-12981 | NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an addforum action. NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an addforum action. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2017-12776 +1 in the same advisory: …12680 | SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport parameter. SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport parameter. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2017-12909 | SQL injection vulnerability in modtask.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parameter. SQL injection vulnerability in modtask.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parameter. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2017-12798 | Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the q parameter to searchsuggest.php. Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the q parameter to searchsuggest.php. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2017-12777 | Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via some parameter to usersearch.php. Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via some parameter to usersearch.php. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2017-12655 | Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the query parameter to log.php in a dailylog action. Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the query parameter to log.php in a dailylog action. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2017-11651 | NexusPHP V1.5 has XSS via a javascript: NexusPHP V1.5 has XSS via a javascript: or data: URL in a UBBCode url tag. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — |