First published: Wed Aug 10 2005(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitrary web script or HTML via the (1) bodycolor, (2) backimage, (3) theme, or (4) logo parameter to structure.php, (5) admin, (6) admin_mail, or (7) back parameter to footer.php, or (8) the message body in a news post.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb | =2.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2539 is classified as having a moderate severity due to its potential for cross-site scripting attacks.
To fix CVE-2005-2539, update FlatNuke to the latest version or apply security patches that address the XSS vulnerabilities.
CVE-2005-2539 affects users of FlatNuke version 2.5.5 and possibly earlier versions.
CVE-2005-2539 can be exploited through parameters like bodycolor, backimage, theme, or logo in structure.php.
CVE-2005-2539 can enable remote attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.