Back
CVE-2004-2354
SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-site scripting (XSS) attacks when MySQL errors are triggered.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (10)
| Vendor | Product | Version |
|---|---|---|
| francisco_burzi | php-nuke | 6.5 |
| francisco_burzi | php-nuke | 6.5_beta1 |
| francisco_burzi | php-nuke | 6.5_final |
| francisco_burzi | php-nuke | 6.5_rc1 |
| francisco_burzi | php-nuke | 6.5_rc2 |
| francisco_burzi | php-nuke | 6.5_rc3 |
| francisco_burzi | php-nuke | 6.6 |
| francisco_burzi | php-nuke | 6.7 |
| francisco_burzi | php-nuke | 6.9 |
| warpspeed | 4nguestbook | 0.92 |
GitHub Security Advisory GHSA-r496-rh9q-6768
SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote...
References (4)
Risk Scores
CVSS Score
6.8 / 10
EPSS Score
1.49%
Top 28% most likely to be exploited
Threat Score
27.6 / 100
Data Sources
NVD
EPSS
GitHub