CVE-2004-2294: XSS
Canonicalize-before-filter error in the sendreview function in the Reviews module for PHP-Nuke 6.0 to 7.3 allows remote attackers to inject arbitrary web script or HTML via hex-encoded XSS sequences in the text parameter, which is checked for dangerous sequences before it is canonicalized, leading to a cross-site scripting (XSS) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2294?
CVE-2004-2294 is considered a medium severity vulnerability due to its potential for remote script injection.
How do I fix CVE-2004-2294?
To fix CVE-2004-2294, upgrade PHP-Nuke to a version that has addressed this vulnerability.
Who is affected by CVE-2004-2294?
Users of PHP-Nuke versions 6.0 to 7.3 are affected by CVE-2004-2294.
What type of vulnerability is CVE-2004-2294?
CVE-2004-2294 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
Can CVE-2004-2294 be exploited remotely?
Yes, CVE-2004-2294 can be exploited remotely due to the nature of the vulnerability allowing attack via user input.