First published: Mon Dec 31 2001(Updated: )
Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) uname parameter in user.php, (2) ttitle, letter and file parameters in modules.php, (3) subject, story and storyext parameters in submit.php, (4) upload parameter in admin.php and (5) fname parameter in friend.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Francisco Burzi PHP-Nuke | =4.0 | |
Francisco Burzi PHP-Nuke | =5.3.1 | |
Francisco Burzi PHP-Nuke | =5.1 | |
Francisco Burzi PHP-Nuke | =4.3 | |
Francisco Burzi PHP-Nuke | =4.4 | |
Francisco Burzi PHP-Nuke | =3.0 | |
Francisco Burzi PHP-Nuke | =5.0 | |
Francisco Burzi PHP-Nuke | =5.2a | |
Francisco Burzi PHP-Nuke | =5.0.1 | |
Francisco Burzi PHP-Nuke | =5.2 | |
Francisco Burzi PHP-Nuke | =4.4.1a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.