Vulnerabilities > CVE-2006-3948 - Cross-Site Scripting vulnerability in PHPNuke INP

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
php-nuke
exploit available

Summary

Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke INP allows remote attackers to inject arbitrary web script or HTML via the query parameter.

Vulnerable Configurations

Part Description Count
Application
Php-Nuke
1

Exploit-Db

descriptionPHPNuke INP Modules.PHP Cross-Site Scripting Vulnerability. CVE-2006-3948. Webapps exploit for php platform
idEDB-ID:28294
last seen2016-02-03
modified2006-07-28
published2006-07-28
reporterl2odon
sourcehttps://www.exploit-db.com/download/28294/
titlePHPNuke INP Modules.PHP Cross-Site Scripting Vulnerability