Exploitation Summary
EIP tracks 4 public exploits for CVE-2004-1912. PoCs published by Janek Vind.
AI-analyzed exploit summary The provided text describes vulnerabilities in NukeCalendar, a PHP-Nuke module, including path disclosure, SQL injection, and XSS. It includes an example URL demonstrating a potential SQL injection vector via the 'eid' parameter.
Description
The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke, allow remote attackers to obtain sensitive information via a URL with an invalid argument, which reveals the full path in an error message.
Exploits (4)
The provided text describes vulnerabilities in NukeCalendar, a PHP-Nuke module, including path disclosure, SQL injection, and XSS. It includes an example URL demonstrating a potential SQL injection vector via the 'eid' parameter.
The provided text describes multiple vulnerabilities in NukeCalendar, a PHP-Nuke module, including path disclosure, SQL injection, and XSS. It references a specific URL path but does not include functional exploit code.
The provided text describes vulnerabilities in NukeCalendar, a PHP-Nuke module, including path disclosure, SQL injection, and XSS. It references a SecurityFocus BID but lacks actual exploit code or technical details.
The provided text describes multiple vulnerabilities in NukeCalendar, a PHP-Nuke module, including path disclosure, SQL injection, and XSS. It references a SecurityFocus BID but lacks actual exploit code or technical details.