First published: Fri Jan 05 2007(Updated: )
Cross-site scripting (XSS) vulnerability in Nuked Klan 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a getURL statement in a .swf file, as demonstrated by "Remote Cookie Disclosure." NOTE: it could be argued that this is an issue in Shockwave instead of Nuked Klan.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nuked-klan Partenaires Module | =1.2 | |
Nuked-klan Partenaires Module | =1.4 | |
Nuked-klan Partenaires Module | =1.2_beta | |
Nuked-klan Partenaires Module | =1.3 | |
Nuked-klan Partenaires Module | =1.5 | |
Nuked-klan Partenaires Module | =1.7 | |
Nuked-klan Partenaires Module | =1.5_sp2 | |
Nuked-klan Partenaires Module | =1.3_beta | |
=1.2 | ||
=1.2_beta | ||
=1.3 | ||
=1.3_beta | ||
=1.4 | ||
=1.5 | ||
=1.5_sp2 | ||
=1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0083 is classified as a medium severity vulnerability due to its potential to enable cross-site scripting attacks.
To fix CVE-2007-0083, update your Nuked Klan software to a version that addresses this XSS vulnerability.
CVE-2007-0083 affects Nuked Klan versions 1.2 through 1.7, including all beta releases.
CVE-2007-0083 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts.
Yes, CVE-2007-0083 can lead to remote attacks, allowing attackers to disclose sensitive information through script injection.