Vulnerabilities > CVE-2004-2354 - Cross-Site Scripting vulnerability in 4Nguestbook
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-site scripting (XSS) attacks when MySQL errors are triggered.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 9 | |
Application | 1 |