CVE-2004-2354

SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-site scripting (XSS) attacks when MySQL errors are triggered.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:francisco_burzi:php-nuke:6.5:*:*:*:*:*:*:*
cpe:2.3:a:francisco_burzi:php-nuke:6.5_beta1:*:*:*:*:*:*:*
cpe:2.3:a:francisco_burzi:php-nuke:6.5_final:*:*:*:*:*:*:*
cpe:2.3:a:francisco_burzi:php-nuke:6.5_rc1:*:*:*:*:*:*:*
cpe:2.3:a:francisco_burzi:php-nuke:6.5_rc2:*:*:*:*:*:*:*
cpe:2.3:a:francisco_burzi:php-nuke:6.5_rc3:*:*:*:*:*:*:*
cpe:2.3:a:francisco_burzi:php-nuke:6.6:*:*:*:*:*:*:*
cpe:2.3:a:francisco_burzi:php-nuke:6.7:*:*:*:*:*:*:*
cpe:2.3:a:francisco_burzi:php-nuke:6.9:*:*:*:*:*:*:*
cpe:2.3:a:warpspeed:4nguestbook:0.92:*:*:*:*:*:*:*

History

20 Nov 2024, 23:53

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2004-03/0139.html - Exploit, Vendor Advisory () http://archives.neohapsis.com/archives/bugtraq/2004-03/0139.html - Exploit, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/15478 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/15478 -

Information

Published : 2004-12-31 05:00

Updated : 2024-11-20 23:53


NVD link : CVE-2004-2354

Mitre link : CVE-2004-2354

CVE.ORG link : CVE-2004-2354


JSON object : View

Products Affected

warpspeed

  • 4nguestbook

francisco_burzi

  • php-nuke