cbcvebase.
CVE-2004-2354
published 2004-12-31

CVE-2004-2354: SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to…

PriorityP419medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.49%
70.9th percentile
SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-site scripting (XSS) attacks when MySQL errors are triggered.

Affected

10 ranges
VendorProductVersion rangeFixed in
francisco_burziphp-nuke
francisco_burziphp-nuke
francisco_burziphp-nuke
francisco_burziphp-nuke
francisco_burziphp-nuke
francisco_burziphp-nuke
francisco_burziphp-nuke
francisco_burziphp-nuke
francisco_burziphp-nuke
warpspeed4nguestbook
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.