CVE-2004-2752 Information

Description

Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726 and possibly later versions allows remote attackers to inject arbitrary HTML and web script via the ttitle parameter in a viewdownloaddetails action.

Reference

http://securitytracker.com/id?1008629 http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2004-01/0015.html http://www.gulftech.org/01032004.php

Share on: