Skip to content
High Published: Dec 31, 2004 Modified: Apr 03, 2025

CVE-2004-1842

8.8 CVSS Score High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Export CVE-2004-1842 Data:
Share:
Link copied!

Description

Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a URL to admin.php.

CVSS Vector Details

Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Affected Software Configurations

  • a phpnuke php-nuke * * * * * * * *

Weaknesses (CWE)

  • CWE-352

CVE History Timeline

May 27, 2005 17:37 Initial Analysis
Oct 18, 2016 03:01 CVE Modified
Jul 11, 2017 01:31 CVE Modified
Feb 08, 2024 20:46 Modified Analysis
May 14, 2024 01:27 CVE Modified
Nov 20, 2024 23:51 CVE Modified