Vulnerabilities > CVE-2004-2294 - Input Validation vulnerability in PHP-Nuke

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
francisco-burzi
exploit available

Summary

Canonicalize-before-filter error in the send_review function in the Reviews module for PHP-Nuke 6.0 to 7.3 allows remote attackers to inject arbitrary web script or HTML via hex-encoded XSS sequences in the text parameter, which is checked for dangerous sequences before it is canonicalized, leading to a cross-site scripting (XSS) vulnerability.

Exploit-Db

descriptionPHP-Nuke 6.x/7.x Reviews Module Multiple Parameter XSS. CVE-2004-2294. Webapps exploit for php platform
idEDB-ID:24194
last seen2016-02-02
modified2004-06-11
published2004-06-11
reporterJanek Vind
sourcehttps://www.exploit-db.com/download/24194/
titlePHP-Nuke 6.x/7.x Reviews Module Multiple Parameter XSS