Unrated severityNVD Advisory· Published Nov 23, 2004· Updated Jun 16, 2026
CVE-2004-0265
CVE-2004-0265
Description
Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitrary script as other users via URL-encoded (1) title or (2) fname parameters in the News or Reviews modules.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14cpe:2.3:a:francisco_burzi:php-nuke:6.0:*:*:*:*:*:*:*+ 13 more
- cpe:2.3:a:francisco_burzi:php-nuke:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:francisco_burzi:php-nuke:6.5:*:*:*:*:*:*:*
- cpe:2.3:a:francisco_burzi:php-nuke:6.5_beta1:*:*:*:*:*:*:*
- cpe:2.3:a:francisco_burzi:php-nuke:6.5_final:*:*:*:*:*:*:*
- cpe:2.3:a:francisco_burzi:php-nuke:6.5_rc1:*:*:*:*:*:*:*
- cpe:2.3:a:francisco_burzi:php-nuke:6.5_rc2:*:*:*:*:*:*:*
- cpe:2.3:a:francisco_burzi:php-nuke:6.5_rc3:*:*:*:*:*:*:*
- cpe:2.3:a:francisco_burzi:php-nuke:6.6:*:*:*:*:*:*:*
- cpe:2.3:a:francisco_burzi:php-nuke:6.7:*:*:*:*:*:*:*
- cpe:2.3:a:francisco_burzi:php-nuke:6.9:*:*:*:*:*:*:*
- cpe:2.3:a:francisco_burzi:php-nuke:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:francisco_burzi:php-nuke:7.0_final:*:*:*:*:*:*:*
- cpe:2.3:a:francisco_burzi:php-nuke:7.1:*:*:*:*:*:*:*
- (no CPE)range: 6.x-7.1.0
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.