CVE-2007-0083: XSS
Cross-site scripting (XSS) vulnerability in Nuked Klan 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a getURL statement in a .swf file, as demonstrated by "Remote Cookie Disclosure." NOTE: it could be argued that this is an issue in Shockwave instead of Nuked Klan.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0083?
CVE-2007-0083 is classified as a medium severity vulnerability due to its potential to enable cross-site scripting attacks.
How do I fix CVE-2007-0083?
To fix CVE-2007-0083, update your Nuked Klan software to a version that addresses this XSS vulnerability.
What versions of Nuked Klan are affected by CVE-2007-0083?
CVE-2007-0083 affects Nuked Klan versions 1.2 through 1.7, including all beta releases.
What type of vulnerability is CVE-2007-0083?
CVE-2007-0083 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts.
Can CVE-2007-0083 lead to remote attacks?
Yes, CVE-2007-0083 can lead to remote attacks, allowing attackers to disclose sensitive information through script injection.