Vulnerabilities > CVE-2005-4260 - Unspecified vulnerability in Francisco Burzi PHP-Nuke

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
francisco-burzi
exploit available

Summary

Interpretation conflict in includes/mainfile.php in PHP-Nuke 7.9 and later allows remote attackers to perform cross-site scripting (XSS) attacks by replacing the ">" in the tag with a "<", which bypasses the regular expressions that sanitize the data, but is automatically corrected by many web browsers. NOTE: it could be argued that this vulnerability is due to a design limitation of many web browsers; if so, then this should not be treated as a vulnerability in PHP-Nuke.

Exploit-Db

descriptionPHPNuke 7.x Content Filtering Byapss Vulnerability. CVE-2005-4260 . Webapps exploit for php platform
idEDB-ID:26817
last seen2016-02-03
modified2005-12-14
published2005-12-14
reporterMaksymilian Arciemowicz
sourcehttps://www.exploit-db.com/download/26817/
titlePHPNuke 7.x Content Filtering Byapss Vulnerability