PT-2004-1419 · Php Nuke · Php-Nuke
Published
2004-03-18
·
Updated
2017-07-11
·
CVE-2004-0265
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Php-Nuke versions 6.x through 7.1.0
Description
A cross-site scripting (XSS) issue exists, allowing remote attackers to execute arbitrary scripts as other users. This is achieved via URL-encoded
title or fname parameters in the News or Reviews modules.Recommendations
For Php-Nuke versions 6.x through 7.1.0, consider disabling the News and Reviews modules until a patch is available to prevent exploitation of the XSS vulnerability. Restrict access to these modules to minimize the risk of arbitrary script execution. Avoid using the
title and fname parameters in the affected modules until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Php-Nuke