PHP-Nuke 7.4 has a cross site scripting flaw that allows an attacker the ability to post messages in a system newsletter.
70838e1167350de5c53df0b19021ae1a35f30f117a6a21475b296353ab6f21fa
PHP-Nuke 7.4 has a cross site scripting flaw that allows an attacker the ability to post global homepage messages.
03dcede6b00dd60a67938196af5367683c8269fbceb7a204b1678875a1a86174
PHP-Nuke 7.4 has a cross site scripting flaw that allows an attacker the ability to view admin account information. It is an old bug that has a patch that can be bypassed if the data is sent via a POST instead of a GET.
0a2035b56855d79436e78d364d0652febcd135bfc23ada43fefd055e73b5d43b
PHP-Nuke 7.4 has a cross site scripting flaw that allows an attacker the ability to delete any admin account. It is an old bug that has a patch that can be bypassed if the data is sent via a POST instead of a GET.
51573d83c3c65065bed02550784dc40a4c140a5fac13c9ead8bf3bd94ee4981f
PHP-Nuke 7.4 has a cross site scripting flaw that allows an attacker administrative access.
86c460faff45056828d58aa969a49ccf5f3b3db094aa0e72ad5e081b85ebc211