Vulnerabilities > CVE-2001-1524 - Cross-Site Scripting vulnerability in PHPNuke

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
francisco-burzi
exploit available

Summary

Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) uname parameter in user.php, (2) ttitle, letter and file parameters in modules.php, (3) subject, story and storyext parameters in submit.php, (4) upload parameter in admin.php and (5) fname parameter in friend.php.

Exploit-Db

  • descriptionPHPNuke 1.0/2.5/3.0/4.x/5.x/6.x/7.x user.php uname Parameter XSS Vulnerability. CVE-2001-1524. Webapps exploit for php platform
    idEDB-ID:21165
    last seen2016-02-02
    modified2001-12-03
    published2001-12-03
    reporterCabezon Aurélien
    sourcehttps://www.exploit-db.com/download/21165/
    titlePHPNuke 1.0/2.5/3.0/4.x/5.x/6.x/7.x user.php uname Parameter XSS Vulnerability
  • descriptionPHPNuke 1.0/2.5/3.0/4.x/5.x/6.x/7.x modules.php Multiple Parameter XSS Vulnerability. CVE-2001-1524. Webapps exploit for php platform
    idEDB-ID:21166
    last seen2016-02-02
    modified2001-12-03
    published2001-12-03
    reporterCabezon Aurélien
    sourcehttps://www.exploit-db.com/download/21166/
    titlePHPNuke 1.0/2.5/3.0/4.x/5.x/6.x/7.x modules.php Multiple Parameter XSS Vulnerability