{"api_version":"1","generated_at":"2026-07-24T19:44:11+00:00","cve":"CVE-2004-2752","urls":{"html":"https://cve.report/CVE-2004-2752","api":"https://cve.report/api/cve/CVE-2004-2752.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-2752","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-2752"},"summary":{"title":"CVE-2004-2752","description":"Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote attackers to inject arbitrary HTML and web script via the ttitle parameter in a viewdownloaddetails action.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.gulftech.org/01032004.php","name":"http://www.gulftech.org/01032004.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Contact Support","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2004-01/0015.html","name":"http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2004-01/0015.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus Bugtraq: PostNuke Issues (0.726 && Possibly Older)","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://securitytracker.com/id?1008629","name":"http://securitytracker.com/id?1008629","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"PostNuke Input Validation Flaw in 'sortby' Variable in 'members_list' Module Permits SQL Injection - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-2752","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-2752","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"2752","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"postnuke_software_foundation","cpe5":"postnuke","cpe6":"0.726","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:36:25.312Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1008629","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1008629"},{"name":"20040102 PostNuke Issues (0.726 && Possibly Older)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2004-01/0015.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.gulftech.org/01032004.php"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote attackers to inject arbitrary HTML and web script via the ttitle parameter in a viewdownloaddetails action."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-11-14T02:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1008629","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1008629"},{"name":"20040102 PostNuke Issues (0.726 && Possibly Older)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2004-01/0015.html"},{"tags":["x_refsource_MISC"],"url":"http://www.gulftech.org/01032004.php"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-2752","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote attackers to inject arbitrary HTML and web script via the ttitle parameter in a viewdownloaddetails action."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1008629","refsource":"SECTRACK","url":"http://securitytracker.com/id?1008629"},{"name":"20040102 PostNuke Issues (0.726 && Possibly Older)","refsource":"BUGTRAQ","url":"http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2004-01/0015.html"},{"name":"http://www.gulftech.org/01032004.php","refsource":"MISC","url":"http://www.gulftech.org/01032004.php"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-2752","datePublished":"2007-11-14T02:00:00.000Z","dateReserved":"2007-11-13T00:00:00.000Z","dateUpdated":"2024-09-17T02:21:24.091Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:postnuke_software_foundation:postnuke:0.726:*:*:*:*:*:*:*","matchCriteriaId":"EED5E57D-A2EA-43C7-A29B-537FDE0656A2"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"2752","Ordinal":"1","Title":"CVE-2004-2752","CVE":"CVE-2004-2752","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"2752","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote attackers to inject arbitrary HTML and web script via the ttitle parameter in a viewdownloaddetails action.","Type":"Description","Title":"CVE-2004-2752"},{"CveYear":"2004","CveId":"2752","Ordinal":"2","NoteData":"2007-11-13","Type":"Other","Title":"Published"}]}}}