Vulnerabilities > CVE-2005-1023 - Unspecified vulnerability in Francisco Burzi PHP-Nuke

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
francisco-burzi
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) min parameter to the Search module, (2) the categories parameter to the FAQ module, or (3) the ltr parameter to the Encyclopedia module. NOTE: the bid parameter issue in banners.php is already an item in CVE-2005-1000.

Exploit-Db

descriptionPHP-Nuke 6.x/7.x FAQ Module categories Parameter XSS. CVE-2005-1023. Webapps exploit for java platform
idEDB-ID:24190
last seen2016-02-02
modified2004-06-11
published2004-06-11
reporterJanek Vind
sourcehttps://www.exploit-db.com/download/24190/
titlePHP-Nuke 6.x/7.x FAQ Module categories Parameter XSS