CVE-2004-1913
NukeCalendar 1.1.a for PHP-Nuke - Cross-Site Scripting via eid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1913. PoCs published by Janek Vind.
AI-analyzed exploit summary The provided text describes multiple vulnerabilities in NukeCalendar, a PHP-Nuke module, including XSS, SQL injection, and path disclosure. It includes a sample XSS payload URL but lacks executable exploit code.
Description
Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject arbitrary web script or HTML via the eid parameter.
Exploits (1)
The provided text describes multiple vulnerabilities in NukeCalendar, a PHP-Nuke module, including XSS, SQL injection, and path disclosure. It includes a sample XSS payload URL but lacks executable exploit code.