CVE-2004-1840: XSS
Multiple cross-site scripting (XSS) vulnerabilities in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the (1) screen parameter to modules.php, (2) modulename parameter to title.php, (3) sortby parameter to modules.php, or (4) overview parameter to modules.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1840?
CVE-2004-1840 is classified as a moderate severity vulnerability, as it allows cross-site scripting (XSS) attacks that can compromise user sessions.
How do I fix CVE-2004-1840?
To fix CVE-2004-1840, update PHP-Nuke to the latest version where the XSS vulnerabilities have been patched.
What versions of PHP-Nuke are affected by CVE-2004-1840?
CVE-2004-1840 affects multiple versions of PHP-Nuke including versions 6.5, 6.7, 6.6, 6.9, and 7.0.
What type of vulnerability is CVE-2004-1840?
CVE-2004-1840 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages.
Can CVE-2004-1840 lead to data breaches?
Yes, CVE-2004-1840 can potentially lead to data breaches by allowing attackers to steal user credentials or session cookies.