Show plain JSON{"id": "CVE-2004-2354", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 6.8, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": true, "userInteractionRequired": false}]}, "published": "2004-12-31T05:00:00.000", "references": [{"url": "http://archives.neohapsis.com/archives/bugtraq/2004-03/0139.html", "tags": ["Exploit", "Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/15478", "source": "cve@mitre.org"}, {"url": "http://archives.neohapsis.com/archives/bugtraq/2004-03/0139.html", "tags": ["Exploit", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/15478", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-Other"}]}], "descriptions": [{"lang": "en", "value": "SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-site scripting (XSS) attacks when MySQL errors are triggered."}], "lastModified": "2024-11-20T23:53:08.313", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:francisco_burzi:php-nuke:6.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "23264211-2992-4222-9B96-5ABEE1332C5B"}, {"criteria": "cpe:2.3:a:francisco_burzi:php-nuke:6.5_beta1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B7F76C32-E24D-4B62-88CE-2D23F457573B"}, {"criteria": "cpe:2.3:a:francisco_burzi:php-nuke:6.5_final:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F90A3E1F-0371-45C0-A165-55D94A62C3DA"}, {"criteria": "cpe:2.3:a:francisco_burzi:php-nuke:6.5_rc1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F80A5D98-6C48-461F-8B96-BD32A96CDCA1"}, {"criteria": "cpe:2.3:a:francisco_burzi:php-nuke:6.5_rc2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "92F4E55E-4424-4EC8-8013-9A0FFE7D3658"}, {"criteria": "cpe:2.3:a:francisco_burzi:php-nuke:6.5_rc3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9DA61C83-9CE0-4B5E-A8A1-B9C5C9D74084"}, {"criteria": "cpe:2.3:a:francisco_burzi:php-nuke:6.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8B13CCAA-839F-406D-A7F3-975B4780425A"}, {"criteria": "cpe:2.3:a:francisco_burzi:php-nuke:6.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1D375197-0087-479C-991B-964FB83644F4"}, {"criteria": "cpe:2.3:a:francisco_burzi:php-nuke:6.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "70F6320E-314D-4A8F-BC9A-29F730035C68"}, {"criteria": "cpe:2.3:a:warpspeed:4nguestbook:0.92:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F843038F-A98A-4FE7-9F31-AC614C776335"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}