Vulnerability Description
SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-site scripting (XSS) attacks when MySQL errors are triggered.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Francisco Burzi | Php-Nuke | 6.5 |
| Warpspeed | 4Nguestbook | 0.92 |
References
- http://archives.neohapsis.com/archives/bugtraq/2004-03/0139.htmlExploitVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15478
- http://archives.neohapsis.com/archives/bugtraq/2004-03/0139.htmlExploitVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15478
FAQ
What is CVE-2004-2354?
CVE-2004-2354 is a vulnerability with a CVSS score of 6.8 (MEDIUM). SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-si...
How severe is CVE-2004-2354?
CVE-2004-2354 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-2354?
Check the references section above for vendor advisories and patch information. Affected products include: Francisco Burzi Php-Nuke, Warpspeed 4Nguestbook.