Vulnerability Name: | CVE-2004-0737 (CCN-16721) | ||||||||
Assigned: | 2004-07-17 | ||||||||
Published: | 2004-07-17 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Multiple cross-site scripting vulnerabilities in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) max, (3) sel1, (4) sel2, (5) sel3, (6) sel4, (7) sel5, (8) match, (9) mod1, (10) mod2, or (11) mod3 parameters. | ||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Fri Jul 16 2004 - 17:14:41 CDT [waraxe-2004-SA#035 - Multiple security holes in PhpNuke - part 2] Source: CCN Type: BugTraq Mailing List, Sun Jul 18 2004 - 08:54:08 CDT [waraxe-2004-SA#036 - Multiple security holes in PhpNuke - part 3] Source: MITRE Type: CNA CVE-2004-0737 Source: BUGTRAQ Type: UNKNOWN 20040718 [waraxe-2004-SA#036 - Multiple security holes in PhpNuke - part 3] Source: CCN Type: OSVDB ID: 7949 PHP-Nuke Search Module index.php Multiple Parameter XSS Source: CCN Type: BID-10741 Multiple PHPNuke SQL Injection And Cross-Site Scripting Vulnerabilities Source: XF Type: UNKNOWN phpnuke-search-module-xss(16721) Source: XF Type: UNKNOWN phpnuke-search-module-xss(16721) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |