First published: Fri Jul 23 2004(Updated: )
Cross-site scripting (XSS) vulnerability in index.php in the Search module for Php-Nuke allows remote attackers to inject arbitrary script as other users via the input field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP-Nuke | =8.0_final |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0731 has a medium severity rating due to the potential for XSS attacks that could compromise user data.
To fix CVE-2004-0731, upgrade to a later version of PHP-Nuke that includes patches for this XSS vulnerability.
The implications of CVE-2004-0731 include the risk of unauthorized script execution in users' browsers, leading to potential information theft or session hijacking.
CVE-2004-0731 affects users and administrators of PHP-Nuke version 8.0_final, particularly those using the Search module.
Yes, CVE-2004-0731 can be exploited remotely by attackers through the input field of the Search module.