First published: Thu Aug 31 2006(Updated: )
Incomplete blacklist vulnerability in the nk_CSS function in nuked.php in Nuked-Klan 1.7 SP4.3 allows remote attackers to bypass anti-XSS features and inject arbitrary web script or HTML via JavaScript in an attribute value that is not in the blacklist, as demonstrated using the STYLE attribute of a B element.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nuked-klan Partenaires Module | =1.7_sp4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4480 is classified as a medium severity vulnerability due to its potential to allow cross-site scripting (XSS) attacks.
To fix CVE-2006-4480, update to a later version of Nuked-Klan that addresses the incomplete blacklist vulnerability.
CVE-2006-4480 affects Nuked-Klan version 1.7 SP4.3.
CVE-2006-4480 enables attackers to inject arbitrary web scripts or HTML, facilitating cross-site scripting (XSS) attacks.
Yes, CVE-2006-4480 can be exploited remotely by attackers to bypass anti-XSS features.