CVE Vulnerabilities

CVE-2004-2354

Published: Dec 31, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-site scripting (XSS) attacks when MySQL errors are triggered.

Affected Software

Name Vendor Start Version End Version
Php-nuke Francisco_burzi 6.5 6.5
Php-nuke Francisco_burzi 6.5_beta1 6.5_beta1
Php-nuke Francisco_burzi 6.5_final 6.5_final
Php-nuke Francisco_burzi 6.5_rc1 6.5_rc1
Php-nuke Francisco_burzi 6.5_rc2 6.5_rc2
Php-nuke Francisco_burzi 6.5_rc3 6.5_rc3
Php-nuke Francisco_burzi 6.6 6.6
Php-nuke Francisco_burzi 6.7 6.7
Php-nuke Francisco_burzi 6.9 6.9
4nguestbook Warpspeed 0.92 0.92

References