CVE-2004-2354: XSS
SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-site scripting (XSS) attacks when MySQL errors are triggered.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2354?
CVE-2004-2354 is considered to have a high severity due to its potential for remote SQL injection and XSS attacks.
How do I fix CVE-2004-2354?
To fix CVE-2004-2354, upgrade to a patched version of 4nGuestbook or implement input validation to prevent SQL injection.
What are the affected versions of software associated with CVE-2004-2354?
The affected software versions include PHP-Nuke 6.5 through 6.9 and 4nGuestbook 0.92.
What types of attacks can CVE-2004-2354 facilitate?
CVE-2004-2354 can facilitate SQL injection attacks and cross-site scripting (XSS) attacks.
How can I mitigate the risks of CVE-2004-2354?
Mitigating the risks of CVE-2004-2354 involves ensuring proper user input sanitization and using updated software versions.