First published: Tue Aug 01 2006(Updated: )
Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke INP allows remote attackers to inject arbitrary web script or HTML via the query parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHP-Nuke |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3948 is classified as a high severity vulnerability due to its potential for remote code execution through cross-site scripting.
To fix CVE-2006-3948, upgrade to a patched version of PHP-Nuke or implement input validation to sanitize the query parameters.
CVE-2006-3948 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages.
The potential impacts of CVE-2006-3948 include exposure of sensitive user information, session hijacking, and exploitation of user trust.
Users of PHP-Nuke INP versions that haven't been patched are affected by CVE-2006-3948.