Multiple cross-site scripting (XSS) vulnerabilities in the Search Module in PHP-Nuke allow remote malicious users to inject arbitrary web script or HTML via a trailing "<" instead of a ">" in (1) the onerror attribute of an IMG element, (2) the onload attribute of an IFRAME element, or (3) redirect users to other sites via the META tag.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
phpnuke php-nuke 7.5 |
||
phpnuke php-nuke 7.6 |
||
phpnuke php-nuke 7.0 |
||
phpnuke php-nuke 7.7 |
||
phpnuke php-nuke 7.8 |
||
phpnuke php-nuke 7.1 |
||
phpnuke php-nuke 7.2 |
||
phpnuke php-nuke 7.9 |
||
phpnuke php-nuke 8.0 |
||
phpnuke php-nuke 7.3 |
||
phpnuke php-nuke 7.4 |