4.3
CVSSv2

CVE-2005-4260

Published: 15/12/2005 Updated: 19/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Interpretation conflict in includes/mainfile.php in PHP-Nuke 7.9 and later allows remote malicious users to perform cross-site scripting (XSS) attacks by replacing the ">" in the tag with a "<", which bypasses the regular expressions that sanitize the data, but is automatically corrected by many web browsers. NOTE: it could be argued that this vulnerability is due to a design limitation of many web browsers; if so, then this should not be treated as a vulnerability in PHP-Nuke.

Vulnerable Product Search on Vulmon Subscribe to Product

francisco burzi php-nuke 7.3

francisco burzi php-nuke 7.6

francisco burzi php-nuke 7.1

francisco burzi php-nuke 7.2

francisco burzi php-nuke 7.7

francisco burzi php-nuke 7.8

francisco burzi php-nuke 7.0

francisco burzi php-nuke 7.9

Exploits

source: wwwsecurityfocuscom/bid/15855/info PHPNuke is prone to a content filtering bypass vulnerability This issue can allow an attacker to bypass content filters and potentially carry out cross-site scripting, HTML injection and other attacks PHPNuke 79 and prior versions are reported to be vulnerable URI: wwwexamplecom/[ ...