CVE-2005-2689: XSS
Published Aug 24, 2005
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote attackers to inject arbitrary web script or HTML via (1) the moderate parameter to the Comments module or (2) htmltext parameter to html/user.php.
Affected Software
1 affected component
Postnuke Software Foundation Postnuke=0.76_rc4b
Event History
Aug 24, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2689?
CVE-2005-2689 has a medium severity rating due to the potential for exploitation via cross-site scripting.
2
How do I fix CVE-2005-2689?
To fix CVE-2005-2689, you should upgrade to a newer version of PostNuke that addresses this cross-site scripting vulnerability.
3
What are the main vulnerabilities in CVE-2005-2689?
CVE-2005-2689 includes multiple cross-site scripting vulnerabilities in the Comments module and html/user.php file.
4
Which versions of PostNuke are affected by CVE-2005-2689?
CVE-2005-2689 affects PostNuke version 0.76_RC4b.
5
Can CVE-2005-2689 be exploited remotely?
Yes, CVE-2005-2689 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.