PT-2004-1419 · Php Nuke · Php-Nuke

Published

2004-03-18

·

Updated

2017-07-11

·

CVE-2004-0265

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Php-Nuke versions 6.x through 7.1.0
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to execute arbitrary scripts as other users. This is achieved via URL-encoded title or fname parameters in the News or Reviews modules.
Recommendations For Php-Nuke versions 6.x through 7.1.0, consider disabling the News and Reviews modules until a patch is available to prevent exploitation of the XSS vulnerability. Restrict access to these modules to minimize the risk of arbitrary script execution. Avoid using the title and fname parameters in the affected modules until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0265

Affected Products

Php-Nuke