CVE-2005-1000: XSS
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the bid parameter to the EmailStats op in banners.pgp, (2) the ratenum parameter in the TopRated and MostPopular actions in the WebLinks module, (3) the ttitle parameter in the viewlinkdetails, viewlinkeditorial, viewlinkcomments, and ratelink actions in the WebLinks module, or (4) the username parameter in the YourAccount module.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1000?
CVE-2005-1000 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2005-1000?
To fix CVE-2005-1000, you should upgrade your PHP-Nuke installation to a more secure version than 7.6.
What causes CVE-2005-1000?
CVE-2005-1000 is caused by multiple cross-site scripting vulnerabilities in PHP-Nuke 7.6 that allow injection of arbitrary web scripts.
Which versions of PHP-Nuke are affected by CVE-2005-1000?
CVE-2005-1000 affects PHP-Nuke version 7.6.
Can CVE-2005-1000 lead to data theft?
Yes, CVE-2005-1000 can lead to data theft as attackers can execute arbitrary scripts in the user's browser.