Vulnerabilities
Vulnerable Software
Cross-site scripting (XSS) vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to inject arbitrary HTML or web script via the (1) cat parameter in a CatView function or (2) jokeid parameter in a JokeView function.
CVSS Score
4.3
EPSS Score
0.004
Published
2004-05-08
SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid parameter.
CVSS Score
4.6
EPSS Score
0.003
Published
2004-05-08
NukeJokes 1.7 and 2 Beta allows remote attackers to obtain the full path of the server via (1) a direct call to mainfunctions.php, (2) an invalid jokeid parameter in a JokeView function or (3) an invalid cat parameter in a CatView function, which reveals the path in a PHP error message.
CVSS Score
5.0
EPSS Score
0.004
Published
2004-05-08


Contact Us

Shodan ® - All rights reserved