CVE-2008-5039: XSS
Published Nov 12, 2008
·Updated
Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inject arbitrary web script or HTML via the tid parameter in a team action to modules.php.
Affected Software
3 affected components
Phpnuke Php-nuke
PHP-Nuke League module
PHP-Nuke League module=2.4
Event History
Nov 12, 2008
CVE Published
via MITRE·08:18 PM
Data Sourced
via MITRE·08:18 PM
Description
Data Sourced
09:09 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-5039?
CVE-2008-5039 has a medium severity rating due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2008-5039?
To fix CVE-2008-5039, update the League module of PHP-Nuke to a version that is not vulnerable, ideally version 2.5 or later if available.
3
What software is affected by CVE-2008-5039?
CVE-2008-5039 specifically affects the League module for PHP-Nuke version 2.4.
4
Can CVE-2008-5039 be exploited remotely?
Yes, CVE-2008-5039 can be exploited remotely by attackers through the tid parameter in team actions.
5
Is CVE-2008-5039 a common vulnerability?
CVE-2008-5039 is known but not widely reported among current vulnerabilities due to the older version of PHP-Nuke it affects.