PHP-Nuke 5.1 stores user and administrator passwords in a base-64 encoded cookie, which could allow remote attackers to gain privileges by stealing or sniffing the cookie and decoding it.
https://exchange.xforce.ibmcloud.com/vulnerabilities/7596
https://euvd.enisa.europa.eu/vulnerability/EUVD-2001-0894