Vulnerabilities > CVE-2005-4260 - Unspecified vulnerability in Francisco Burzi PHP-Nuke
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
Interpretation conflict in includes/mainfile.php in PHP-Nuke 7.9 and later allows remote attackers to perform cross-site scripting (XSS) attacks by replacing the ">" in the tag with a "<", which bypasses the regular expressions that sanitize the data, but is automatically corrected by many web browsers. NOTE: it could be argued that this vulnerability is due to a design limitation of many web browsers; if so, then this should not be treated as a vulnerability in PHP-Nuke.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 8 |
Exploit-Db
description | PHPNuke 7.x Content Filtering Byapss Vulnerability. CVE-2005-4260 . Webapps exploit for php platform |
id | EDB-ID:26817 |
last seen | 2016-02-03 |
modified | 2005-12-14 |
published | 2005-12-14 |
reporter | Maksymilian Arciemowicz |
source | https://www.exploit-db.com/download/26817/ |
title | PHPNuke 7.x Content Filtering Byapss Vulnerability |