Vulnonym.org

CVE-2004-2293 - Emanative Programmers

Description

Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.0 to 7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) eid parameter or (2) query parameter to the Encyclopedia module (3) preview_review function in the Reviews module as demonstrated by the url cover rlanguage and hits parameters or (4) savecomment function in the Reviews module as demonstrated using the uname parameter. NOTE: the Faq/categories and Encyclopedia/ltr issues are already covered by CVE-2005-1023.

Reference

http://www.securityfocus.com/archive/1/365865 http://www.securityfocus.com/bid/10524 http://www.osvdb.org/6997 http://www.osvdb.org/6998 http://www.osvdb.org/6999 http://secunia.com/advisories/11852 https://exchange.xforce.ibmcloud.com/vulnerabilities/16406 Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.0 to 7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) eid parameter or (2) query parameter to the Encyclopedia module (3) preview_review function in the Reviews module as demonstrated by the url cover rlanguage and hits parameters or (4) savecomment function in the Reviews module as demonstrated using the uname parameter. NOTE: the Faq/categories and Encyclopedia/ltr issues are already covered by CVE-2005-1023.