First published: Fri Dec 31 2004(Updated: )
Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote attackers to inject arbitrary HTML and web script via the ttitle parameter in a viewdownloaddetails action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb | =0.726 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2752 has a moderate severity rating due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2004-2752, update the PostNuke software to a version later than 0.726 that addresses this vulnerability.
Attackers can inject arbitrary HTML and web scripts through the ttitle parameter, which can lead to unauthorized actions or data theft.
CVE-2004-2752 affects PostNuke versions up to 0.726, and potentially later versions if not patched.
CVE-2004-2752 is considered a common vulnerability due to the prevalence of XSS vulnerabilities in web applications.