Vulnerabilities > CVE-2004-1957 - Cross-Site Scripting And Path Disclosure vulnerability in PostNuke Phoenix

047910
CVSS 2.6 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
high complexity
postnuke-software-foundation
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web script or HTML via the (1) lid and query parameters to the Downloads module, (2) query parameter to the Web_links module, or (3) hlpfile parameter to openwindow.php.

Vulnerable Configurations

Part Description Count
Application
Postnuke_Software_Foundation
1

Exploit-Db

  • descriptionPostNuke Phoenix 0.726 openwindow.php hlpfile Parameter XSS. CVE-2004-1957. Webapps exploit for php platform
    idEDB-ID:24037
    last seen2016-02-02
    modified2004-04-21
    published2004-04-21
    reporterJanek Vind
    sourcehttps://www.exploit-db.com/download/24037/
    titlePostNuke Phoenix 0.726 openwindow.php hlpfile Parameter XSS
  • descriptionPostNuke 0.6/0.7 Downloads Module TTitle Cross-site Scripting Vulnerability. CVE-2004-1957. Webapps exploit for php platform
    idEDB-ID:22997
    last seen2016-02-02
    modified2003-08-08
    published2003-08-08
    reporterLorenzo Hernandez Garcia-Hierro
    sourcehttps://www.exploit-db.com/download/22997/
    titlePostNuke 0.6/0.7 Downloads Module TTitle Cross-Site Scripting Vulnerability