Vulnerability Name: | CVE-2001-1524 (CCN-44762) | ||||||||
Assigned: | 2001-12-03 | ||||||||
Published: | 2001-12-03 | ||||||||
Updated: | 2008-09-10 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) uname parameter in user.php, (2) ttitle, letter and file parameters in modules.php, (3) subject, story and storyext parameters in submit.php, (4) upload parameter in admin.php and (5) fname parameter in friend.php. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Sun Dec 02 2001 - 18:40:13 CST Phpnuke cross site scripting vulnerability Source: CCN Type: BugTraq Mailing List, Fri Dec 14 2001 - 19:47:27 CST Here a few holes that i've found in PHPNuke Source: CCN Type: BugTraq Mailing List, Sat Dec 15 2001 - 19:05:45 CST Phpnuke module.php vulnerability and PHP error_reporting issue Source: MITRE Type: CNA CVE-2001-1524 Source: CCN Type: Virus.Org Mailing List, 20 Dec 2001 15:06:50 -0000 1 last CSS hole in PHPNuke :) Source: BUGTRAQ Type: UNKNOWN 20011215 PHPNuke holes Source: BUGTRAQ Type: UNKNOWN 20011216 Phpnuke module.php vulnerability and php error_reporting issue Source: BUGTRAQ Type: UNKNOWN 20011203 Phpnuke Cross site scripting vulnerability Source: VULN-DEV Type: UNKNOWN 20011220 1 last CSS hole in PHPNuke :) Source: CCN Type: PHP-Nuke Web site PHP-Nuke Source: CONFIRM Type: Patch http://prdownloads.sourceforge.net/phpnuke/PHP-Nuke-5.5.tar.gz Source: XF Type: UNKNOWN phpnuke-postnuke-css(7654) Source: CCN Type: OSVDB ID: 20230 PHP-Nuke user.php uname Parameter XSS Source: CCN Type: OSVDB ID: 20231 PHP-Nuke modules.php Multiple Parameter XSS Source: CCN Type: OSVDB ID: 20232 PHP-Nuke submit.php Multiple Parameter XSS Source: CCN Type: OSVDB ID: 20233 PHP-Nuke admin.php upload Parameter XSS Source: CCN Type: OSVDB ID: 20234 PHP-Nuke friend.php fname Parameter XSS Source: BID Type: UNKNOWN 3609 Source: CCN Type: BID-3609 PHPNuke Multiple Cross-Site Scripting Vulnerability Source: XF Type: UNKNOWN phpnuke-user-xss(44762) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |