4.3
CVSSv2

CVE-2005-1000

Published: 02/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 450
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote malicious users to inject arbitrary web script or HTML via (1) the bid parameter to the EmailStats op in banners.pgp, (2) the ratenum parameter in the TopRated and MostPopular actions in the Web_Links module, (3) the ttitle parameter in the viewlinkdetails, viewlinkeditorial, viewlinkcomments, and ratelink actions in the Web_Links module, or (4) the username parameter in the Your_Account module.

Vulnerable Product Search on Vulmon Subscribe to Product

francisco burzi php-nuke 7.6

Exploits

source: wwwsecurityfocuscom/bid/13010/info It is reported that the PHP-Nuke 'Your_Account' module is affected by a cross-site scripting vulnerability This issue is due to a failure of the application to properly sanitize user-supplied URI input This problem presents itself when malicious HTML and script code is sent to the application ...
source: wwwsecurityfocuscom/bid/13026/info PHP-Nuke is reportedly affected by a cross-site scripting vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user This may facilit ...
source: wwwsecurityfocuscom/bid/13025/info PHP-Nuke is reportedly affected by multiple cross-site scripting vulnerabilities in the Web_Links Module These issues are due to a failure in the application to properly sanitize user-supplied input An attacker may leverage these issues to have arbitrary script code executed in the browser of ...
source: wwwsecurityfocuscom/bid/13007/info It is reported that the PHP-Nuke 'Your_Account' module is affected by a cross-site scripting vulnerability This issue is due to a failure of the application to properly sanitize user-supplied URI input This problem presents itself when malicious HTML and script code is sent to the application ...