Lucene search

K
cveMitreCVE-2004-2752
HistoryNov 14, 2007 - 2:00 a.m.

CVE-2004-2752

2007-11-1402:00:00
CWE-79
mitre
web.nvd.nist.gov
24
postnuke
downloads module
xss
cross-site scripting
security vulnerability
cve-2004-2752

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.1

Confidence

High

EPSS

0.002

Percentile

61.0%

Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote attackers to inject arbitrary HTML and web script via the ttitle parameter in a viewdownloaddetails action.

Affected configurations

Nvd
Node
postnuke_software_foundationpostnukeMatch0.726
VendorProductVersionCPE
postnuke_software_foundationpostnuke0.726cpe:2.3:a:postnuke_software_foundation:postnuke:0.726:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.1

Confidence

High

EPSS

0.002

Percentile

61.0%

Related for CVE-2004-2752