4.3
CVSSv2

CVE-2004-2007

Published: 08/05/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote malicious users to inject arbitrary HTML or web script via the (1) cat parameter in a CatView function or (2) jokeid parameter in a JokeView function.

Vulnerable Product Search on Vulmon Subscribe to Product

adam webb nukejokes 1.7

adam webb nukejokes 2.0_beta

Exploits

source: wwwsecurityfocuscom/bid/10306/info It has been reported that the NukeJokes module is affected by multiple input validation vulnerabilities These issues are due to a failure of the application to properly sanitize user supplied user input Multiple SQL injection issues exists due to a failure of the application to do any sanitiza ...