CVE-2003-1547: XSS
Cross-site scripting (XSS) vulnerability in block-Forums.php in the Splatt Forum module for PHP-Nuke 6.x allows remote attackers to inject arbitrary web script or HTML via the subject parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1547?
CVE-2003-1547 is considered a medium severity vulnerability due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2003-1547?
To fix CVE-2003-1547, ensure that your PHP-Nuke installation is updated to a version that mitigates this vulnerability.
What types of attacks are possible with CVE-2003-1547?
CVE-2003-1547 allows attackers to inject arbitrary web scripts or HTML via the subject parameter, leading to potential data theft or session hijacking.
Which versions of PHP-Nuke are affected by CVE-2003-1547?
CVE-2003-1547 affects PHP-Nuke versions 6.5, 6.5_beta1, and all release candidates from 6.5_rc1 to 6.5_rc3.
Is CVE-2003-1547 easy to exploit?
Yes, CVE-2003-1547 can be easily exploited by sending malicious input through the affected subject parameter.