CVE-2004-1842: CSRF
Published Dec 31, 2004
·Updated
Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a URL to admin.php.
Affected Software
14 affected components
Francisco Burzi PHP-Nuke=6.5_beta1
Francisco Burzi PHP-Nuke=6.5
Francisco Burzi PHP-Nuke=7.0
Francisco Burzi PHP-Nuke=7.0_final
Francisco Burzi PHP-Nuke=6.5_rc2
Francisco Burzi PHP-Nuke=6.5_rc3
Francisco Burzi PHP-Nuke=6.0
Francisco Burzi PHP-Nuke=6.5_final
Francisco Burzi PHP-Nuke=6.7
Francisco Burzi PHP-Nuke=6.6
Francisco Burzi PHP-Nuke=6.9
Francisco Burzi PHP-Nuke=7.1
Francisco Burzi PHP-Nuke=6.5_rc1
Phpnuke Php-nuke>=6.0<=7.1
Event History
Dec 31, 2004
CVE Published
05:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1842?
CVE-2004-1842 is considered a high severity vulnerability due to its potential to allow unauthorized administrative access.
2
How do I fix CVE-2004-1842?
To fix CVE-2004-1842, it is recommended to upgrade to a version of PHP-Nuke that is not affected by this vulnerability, specifically versions higher than 7.1.0.
3
What versions of PHP-Nuke are affected by CVE-2004-1842?
CVE-2004-1842 affects PHP-Nuke versions from 6.0 through 7.1.0.
4
Who can exploit the CVE-2004-1842 vulnerability?
Any remote attacker can exploit CVE-2004-1842 to gain unauthorized administrative privileges.
5
What type of vulnerability is CVE-2004-1842?
CVE-2004-1842 is a Cross-Site Request Forgery (CSRF) vulnerability.