First published: Wed Nov 12 2008(Updated: )
Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inject arbitrary web script or HTML via the tid parameter in a team action to modules.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PhpNuke | ||
PHP-Nuke | ||
PHP-Nuke | =2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5039 has a medium severity rating due to the potential for cross-site scripting attacks.
To fix CVE-2008-5039, update the League module of PHP-Nuke to a version that is not vulnerable, ideally version 2.5 or later if available.
CVE-2008-5039 specifically affects the League module for PHP-Nuke version 2.4.
Yes, CVE-2008-5039 can be exploited remotely by attackers through the tid parameter in team actions.
CVE-2008-5039 is known but not widely reported among current vulnerabilities due to the older version of PHP-Nuke it affects.