PT-2004-2828 · Php · Php-Nuke

Janek Vind

+1

·

Published

2004-04-12

·

Updated

2017-07-11

·

CVE-2004-1930

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP-Nuke versions 6.x through 7.2
Description A cross-site scripting (XSS) issue exists in the cookiedecode function in mainfile.php, specifically when themes are used. This allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie.
Recommendations For PHP-Nuke versions 6.x through 7.2, consider disabling the cookiedecode function in mainfile.php as a temporary workaround until a patch is available. Restrict access to themes to minimize the risk of exploitation. Avoid using base64-encoded user parameters or cookies in the affected function until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1930

Affected Products

Php-Nuke