Vulnerabilities (CVE)

Filtered by vendor Nexusphp Project Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-14512 1 Nexusphp Project 1 Nexusphp 2017-09-21 7.5 HIGH 9.8 CRITICAL
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different vulnerability than CVE-2017-12981.
CVE-2017-12776 1 Nexusphp Project 1 Nexusphp 2017-09-19 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport parameter.
CVE-2017-12908 1 Nexusphp Project 1 Nexusphp 2017-08-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the conusr parameter.
CVE-2017-12909 1 Nexusphp Project 1 Nexusphp 2017-08-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in modtask.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parameter.
CVE-2017-12910 1 Nexusphp Project 1 Nexusphp 2017-08-20 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in massmail.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the or parameter.