4.3

CVE-2004-1999

Exploit

Cross-site scripting (XSS) vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to inject arbitrary HTML and web script via the (1) ttitle or (2) sid parameters to modules.php.

Data is provided by the National Vulnerability Database (NVD)
Francisco BurziPhp-nuke Version6.0
Francisco BurziPhp-nuke Version6.5
Francisco BurziPhp-nuke Version6.6
Francisco BurziPhp-nuke Version6.7
Francisco BurziPhp-nuke Version6.8
Francisco BurziPhp-nuke Version6.9
Francisco BurziPhp-nuke Version7.0
Francisco BurziPhp-nuke Version7.1
Francisco BurziPhp-nuke Version7.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.89% 0.733
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N