Vulnerability Name: | CCN-10697 | ||||||
Published: | 2002-11-24 | ||||||
Updated: | 2002-11-24 | ||||||
Summary: | PHP-Nuke is vulnerable to cross-site scripting in multiple modules, caused by improper filtering of HTML tags. A remote attacker could embed malicious script within a URL link to the fetch.php script, which would be executed in the victim's Web browser within the security context of the hosting site, once the link is clicked. An attacker could use these vulnerabilities to steal the victim's cookie-based authentication credentials or launch further attacks against the affected server. | ||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||
CVSS v2 Severity: | 2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N) 2.4 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:H/RL:U/RC:UR)
| ||||||
Vulnerability Consequences: | Gain Access | ||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Sun Nov 24 2002 - 12:09:04 CST Multiple phpNuke Modules Vulnerable to Cross-Site Scripting Source: CCN Type: PHP-Nuke Web site PHP-Nuke Source: CCN Type: BID-6244 PHP-Nuke Multiple Cross Site Scripting Vulnerabilities Source: XF Type: UNKNOWN phpnuke-fetch-xss(10697) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |