Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web script or HTML via the (1) lid and query parameters to the Downloads module, (2) query parameter to the Web_links module, or (3) hlpfile parameter to openwindow.php.
                
            References
                    | Link | Resource | 
|---|---|
| http://marc.info/?l=bugtraq&m=108258902000472&w=2 | |
| http://www.securityfocus.com/bid/10191 | Exploit Vendor Advisory | 
| http://www.waraxe.us/index.php?modname=sa&id=22 | Exploit Vendor Advisory | 
| https://exchange.xforce.ibmcloud.com/vulnerabilities/15934 | 
Configurations
                    History
                    No history.
Information
                Published : 2004-04-21 04:00
Updated : 2017-07-11 01:31
NVD link : CVE-2004-1957
Mitre link : CVE-2004-1957
CVE.ORG link : CVE-2004-1957
JSON object : View
Products Affected
                postnuke_software_foundation
- postnuke
 
CWE
                