CVE-2002-1996: XSS
Published Dec 31, 2002
·Updated
Cross-site scripting (XSS) vulnerability in PostNuke 0.71 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name parameter in modules.php and (2) catid parameter in index.php.
Affected Software
7 affected components
Postnuke Software Foundation Postnuke=0.71
Postnuke Software Foundation Postnuke=0.63
Postnuke Software Foundation Postnuke=0.64
Postnuke Software Foundation Postnuke=0.703
Postnuke Software Foundation Postnuke=0.70
Postnuke Software Foundation Postnuke=0.62
Postnuke Software Foundation Postnuke=0.7
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Jul 14, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
Can CVE-2002-1996 affect user data?
Yes, CVE-2002-1996 can potentially lead to unauthorized access to user data through malicious script execution.