| VID |
21907 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The Nucleus CMS, according to its version number, has multiple vulnerabilities which exist in versions prior to 3.15. Nucleus CMS is an open-source content management system written by PHP. Nucleus CMS versions prior to 3.15 are vulnerable to multiple vulnerabilities, which can be exploited by a remote attacker to conduct cross-site scripting and SQL injection attacks.
* Note: This check solely relied on the version number of Nucleus CMS on the remote Web server to assess this vulnerability, so this might be a false positive.
* References: http://secunia.com/advisories/13136/
* Platforms Affected: The Nucleus Group, Nucleus CMS versions prior to 3.15 Any operating system Any version |
| Recommendation |
Upgrade to the latest version of Nucleus CMS (3.15 or later), available from the Nucleus Group Download Web site at http://nucleuscms.org/download.php |
| Related URL |
CVE-2004-2056 (CVE) |
| Related URL |
11631 (SecurityFocus) |
| Related URL |
18001,18002 (ISS) |
|