Vulnerability Name: | CVE-2004-2293 (CCN-16406) | ||||||||
Assigned: | 2004-06-11 | ||||||||
Published: | 2004-06-11 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.0 to 7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) eid parameter or (2) query parameter to the Encyclopedia module, (3) preview_review function in the Reviews module as demonstrated by the url, cover, rlanguage, and hits parameters, or (4) savecomment function in the Reviews module, as demonstrated using the uname parameter. Note: the Faq/categories and Encyclopedia/ltr issues are already covered by CVE-2005-1023. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Fri Jun 11 2004 - 06:26:27 CDT [waraxe-2004-SA#032 - Multiple security flaws in PhpNuke 6.x - 7.3] Source: MITRE Type: CNA CVE-2004-2293 Source: CCN Type: SA11852 PHP-Nuke Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 11852 Source: OSVDB Type: Exploit 6997 Source: OSVDB Type: Exploit 6998 Source: OSVDB Type: Exploit 6999 Source: CCN Type: OSVDB ID: 6997 PHP-Nuke FAQ Module categories Parameter XSS Source: CCN Type: OSVDB ID: 6998 PHP-Nuke Encyclopedia Module Multiple Function XSS Source: CCN Type: OSVDB ID: 6999 PHP-Nuke Reviews Module Multiple Parameter XSS Source: BUGTRAQ Type: Exploit 20040611 [waraxe-2004-SA#032 - Multiple security flaws in PhpNuke 6.x - 7.3] Source: BID Type: Exploit 10524 Source: CCN Type: BID-10524 PHP-Nuke Multiple Input Validation Vulnerabilities Source: XF Type: UNKNOWN phpnuke-faq-encyclopedia-xss(16406) Source: XF Type: UNKNOWN phpnuke-faq-encyclopedia-xss(16406) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |