4.3
CVSSv2

CVE-2006-3948

Published: 01/08/2006 Updated: 17/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke INP allows remote malicious users to inject arbitrary web script or HTML via the query parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

php-nuke inp

Exploits

source: wwwsecurityfocuscom/bid/19208/info PHPNuke INP is prone to a cross-site scripting vulnerability that affects the 'modulesphp' script The specific version affected is currently unknown wwwexamplecom/[path]/modulesphp?name=Downloads&op=search&query=><script>alert('ARIA')</script>< ...