First published: Mon Mar 15 2004(Updated: )
Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary script as other users by injecting arbitrary script into the z parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Warpspeed 4nalbum Module | =0.92 | |
Warpspeed 4nalbum Module | =0.92 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1818 is considered a medium-severity cross-site scripting (XSS) vulnerability.
To fix CVE-2004-1818, upgrade 4nalbum to the latest version that addresses this vulnerability.
The potential impacts of CVE-2004-1818 include unauthorized script execution that could lead to session hijacking or other malicious actions.
Users of the 4nalbum module version 0.92 for PHP-Nuke between versions 6.5 and 7.0 are affected by CVE-2004-1818.
Yes, CVE-2004-1818 can be exploited remotely by attackers injecting malicious scripts through the vulnerable parameter.