4.3
CVSSv2

CVE-2005-1023

Published: 02/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to 7.6 allow remote malicious users to inject arbitrary web script or HTML via the (1) min parameter to the Search module, (2) the categories parameter to the FAQ module, or (3) the ltr parameter to the Encyclopedia module. NOTE: the bid parameter issue in banners.php is already an item in CVE-2005-1000.

Vulnerable Product Search on Vulmon Subscribe to Product

francisco burzi php-nuke 6.5_rc3

francisco burzi php-nuke 6.6

francisco burzi php-nuke 7.4

francisco burzi php-nuke 7.5

francisco burzi php-nuke 6.5_rc1

francisco burzi php-nuke 6.5_rc2

francisco burzi php-nuke 7.1

francisco burzi php-nuke 7.2

francisco burzi php-nuke 7.3

francisco burzi php-nuke 6.5_beta1

francisco burzi php-nuke 6.5_final

francisco burzi php-nuke 7.0

francisco burzi php-nuke 7.0_final

francisco burzi php-nuke 6.0

francisco burzi php-nuke 6.5

francisco burzi php-nuke 6.7

francisco burzi php-nuke 6.9

francisco burzi php-nuke 7.6

Exploits

source: wwwsecurityfocuscom/bid/10524/info PHP-Nuke is prone to multiple vulnerabilities The issues result from insufficient sanitization of user-supplied data The following specific issues can affect the application: PHP-Nuke is prone to multiple cross-site scripting vulnerabilities These issues affect the 'Faq', 'Encyclopedia' and ' ...