Vulnerabilities > CVE-2004-1930 - Cross-Site Scripting vulnerability in PHP-Nuke CookieDecode

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
francisco-burzi
exploit available

Summary

Cross-site scripting (XSS) vulnerability in the cookiedecode function in mainfile.php for PHP-Nuke 6.x through 7.2, when themes are used, allows remote attackers to inject arbitrary web script or HTML via a base64-encoded user parameter or cookie.

Exploit-Db

descriptionPHP-Nuke 6.x/7.x CookieDecode Cross-Site Scripting Vulnerability. CVE-2004-1930. Webapps exploit for php platform
idEDB-ID:23990
last seen2016-02-02
modified2004-04-13
published2004-04-13
reporterwaraxe
sourcehttps://www.exploit-db.com/download/23990/
titlePHP-Nuke 6.x/7.x CookieDecode Cross-Site Scripting Vulnerability