VID |
21907 |
Severity |
30 |
Port |
80, ... |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
The Nucleus CMS, according to its version number, has multiple vulnerabilities which exist in versions prior to 3.15. Nucleus CMS is an open-source content management system written by PHP. Nucleus CMS versions prior to 3.15 are vulnerable to multiple vulnerabilities, which can be exploited by a remote attacker to conduct cross-site scripting and SQL injection attacks.
* Note: This check solely relied on the version number of Nucleus CMS on the remote Web server to assess this vulnerability, so this might be a false positive.
* References: http://secunia.com/advisories/13136/
* Platforms Affected: The Nucleus Group, Nucleus CMS versions prior to 3.15 Any operating system Any version |
Recommendation |
Upgrade to the latest version of Nucleus CMS (3.15 or later), available from the Nucleus Group Download Web site at http://nucleuscms.org/download.php |
Related URL |
CVE-2004-2056 (CVE) |
Related URL |
11631 (SecurityFocus) |
Related URL |
18001,18002 (ISS) |
|