← Vulnerability feed

Vulnerability record · CVE-2001-0899 · published 16 November 2001

CVE-2001-0899: Phpnuke php-nuke vulnerability

PPhpnuke · Php Nuke

Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variable.

7.5 CVSS 2.0 High EPSS 8.9% · top 4.9%
7.5CVSS 2.0 base score
8.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variable.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2001-0899 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-30177Phpnuke php-nuke sql injection vulnerabilityThere is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execution. This occurs because the …EPSS 2.4%8.8CVE-2004-1842Phpnuke php-nuke cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img ta…EPSS 1.7%7.5CVE-2014-3934Phpnuke php-nuke sql injection vulnerabilitySQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL commands via the topics[] par…EPSS 2.2%7.5CVE-2010-5083Phpnuke php-nuke sql injection vulnerabilitySQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter …EPSS 1.1%7.5CVE-2011-1480Phpnuke php-nuke sql injection vulnerabilitySQL injection vulnerability in admin.php in the administration backend in Francisco Burzi PHP-Nuke 8.0 and earlier allows remote attackers to execute…EPSS 1.2%7.5CVE-2009-1842Phpnuke php-nuke sql injection vulnerabilitySQL injection vulnerability in main/tracking/userLog.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands vi…EPSS 0.96%7.5CVE-2008-6728Phpnuke php-nuke sql injection vulnerabilitySQL injection vulnerability in the Sections module in PHP-Nuke, probably before 8.0, allows remote attackers to execute arbitrary SQL commands via th…EPSS 1.1%7.5CVE-2008-2020E107 vulnerabilityThe CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) phpMyBitT…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2001-0899), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.