CVE-2004-1842
8.8
CVSS Score
High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Link copied!
Description
Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a URL to admin.php.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Software Configurations
- a phpnuke php-nuke * * * * * * * *
Weaknesses (CWE)
- CWE-352
References & External Links
- http://marc.info/?l=bugtraq&m=108006309112075&w=2
- http://secunia.com/advisories/11195
- http://www.securityfocus.com/bid/9895
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15596
- http://marc.info/?l=bugtraq&m=108006309112075&w=2
- http://secunia.com/advisories/11195
- http://www.securityfocus.com/bid/9895
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15596
External Resources
CVE History Timeline
May 27, 2005 17:37
Initial Analysis
Oct 18, 2016 03:01
CVE Modified
Jul 11, 2017 01:31
CVE Modified
Feb 08, 2024 20:46
Modified Analysis
May 14, 2024 01:27
CVE Modified
Nov 20, 2024 23:51
CVE Modified