First published: Wed Jun 08 2005(Updated: )
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the border or back parameters to (1) help.php or (2) footer.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb | =2.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1895 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2005-1895, it is recommended to upgrade FlatNuke to a version later than 2.5.3 where the vulnerability has been patched.
Users of FlatNuke version 2.5.3 are directly affected by CVE-2005-1895.
CVE-2005-1895 can enable attackers to perform cross-site scripting attacks, potentially leading to session hijacking or malicious script execution.
Yes, there are known exploits for CVE-2005-1895 that demonstrate how attackers can exploit the vulnerability to inject scripts.