CVE-2007-1519: XSS
Published Mar 20, 2007
·Updated
Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke 8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search operation in the Downloads module, a different product than CVE-2006-3948.
Affected Software
1 affected component
Phpnuke Php-nuke<=8.0
Event History
Mar 20, 2007
CVE Published
08:19 PM
Mar 21, 2007
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1519?
CVE-2007-1519 is classified as a critical vulnerability due to its potential for XSS exploitation.
2
How do I fix CVE-2007-1519?
To fix CVE-2007-1519, upgrade to a version of PHP-Nuke later than 8.0 that addresses this XSS vulnerability.
3
What products are affected by CVE-2007-1519?
CVE-2007-1519 affects PHP-Nuke versions 8.0 and earlier.
4
What type of attack is enabled by CVE-2007-1519?
CVE-2007-1519 enables remote attackers to perform cross-site scripting (XSS) attacks.
5
In which module does CVE-2007-1519 exist?
CVE-2007-1519 exists in the Downloads module of PHP-Nuke.