4.3
CVSSv2

CVE-2004-2293

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.0 to 7.3 allow remote malicious users to inject arbitrary web script or HTML via the (1) eid parameter or (2) query parameter to the Encyclopedia module, (3) preview_review function in the Reviews module as demonstrated by the url, cover, rlanguage, and hits parameters, or (4) savecomment function in the Reviews module, as demonstrated using the uname parameter. NOTE: the Faq/categories and Encyclopedia/ltr issues are already covered by CVE-2005-1023.

Vulnerable Product Search on Vulmon Subscribe to Product

francisco burzi php-nuke 6.0

francisco burzi php-nuke 6.5

francisco burzi php-nuke 6.7

francisco burzi php-nuke 6.9

francisco burzi php-nuke 6.5_rc1

francisco burzi php-nuke 6.5_rc2

francisco burzi php-nuke 7.2

francisco burzi php-nuke 7.3

francisco burzi php-nuke 6.5_rc3

francisco burzi php-nuke 6.6

francisco burzi php-nuke 6.5_beta1

francisco burzi php-nuke 6.5_final

francisco burzi php-nuke 7.0

francisco burzi php-nuke 7.0_final

francisco burzi php-nuke 7.1

Exploits

source: wwwsecurityfocuscom/bid/10524/info PHP-Nuke is prone to multiple vulnerabilities The issues result from insufficient sanitization of user-supplied data The following specific issues can affect the application: PHP-Nuke is prone to multiple cross-site scripting vulnerabilities These issues affect the 'Faq', 'Encyclopedia' and ...