Vulnerabilities > CVE-2004-1957 - Cross-Site Scripting And Path Disclosure vulnerability in PostNuke Phoenix
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web script or HTML via the (1) lid and query parameters to the Downloads module, (2) query parameter to the Web_links module, or (3) hlpfile parameter to openwindow.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description PostNuke Phoenix 0.726 openwindow.php hlpfile Parameter XSS. CVE-2004-1957. Webapps exploit for php platform id EDB-ID:24037 last seen 2016-02-02 modified 2004-04-21 published 2004-04-21 reporter Janek Vind source https://www.exploit-db.com/download/24037/ title PostNuke Phoenix 0.726 openwindow.php hlpfile Parameter XSS description PostNuke 0.6/0.7 Downloads Module TTitle Cross-site Scripting Vulnerability. CVE-2004-1957. Webapps exploit for php platform id EDB-ID:22997 last seen 2016-02-02 modified 2003-08-08 published 2003-08-08 reporter Lorenzo Hernandez Garcia-Hierro source https://www.exploit-db.com/download/22997/ title PostNuke 0.6/0.7 Downloads Module TTitle Cross-Site Scripting Vulnerability