CVE-2004-2294 Information
Feb 14, 2021
cve
Description
Canonicalize-before-filter error in the send_review function in the Reviews module for PHP-Nuke 6.0 to 7.3 allows remote attackers to inject arbitrary web script or HTML via hex-encoded XSS sequences in the text parameter which is checked for dangerous sequences before it is canonicalized leading to a cross-site scripting (XSS) vulnerability.
Reference
http://secunia.com/advisories/11852 http://www.osvdb.org/6999 http://www.securityfocus.com/archive/1/365865 http://www.securityfocus.com/bid/10524
Share on: