CVE-2004-1818
4nalbum 0.92 for PHP-Nuke 6.5-7.0 - Cross-Site Scripting via z Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1818. PoCs published by Janek Vind.
AI-analyzed exploit summary The provided text describes multiple vulnerabilities in 4nAlbum, including information disclosure, remote file inclusion, XSS, and SQL injection. It outlines affected scripts and attack vectors but does not include executable exploit code.
Description
Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary script as other users by injecting arbitrary script into the z parameter.
Exploits (1)
The provided text describes multiple vulnerabilities in 4nAlbum, including information disclosure, remote file inclusion, XSS, and SQL injection. It outlines affected scripts and attack vectors but does not include executable exploit code.