PHPNuke INP Modules.PHP Cross-Site Scripting Vulnerability
BID:19208
CVE-2006-3948 |Info
PHPNuke INP Modules.PHP Cross-Site Scripting Vulnerability
| Bugtraq ID: | 19208 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 28 2006 12:00AM |
| Updated: | Jul 28 2006 09:32PM |
| Credit: | Discovered by l2odon. |
| Vulnerable: |
PHPNuke INP PHPNuke INP 0 |
| Not Vulnerable: | |
Discussion
PHPNuke INP Modules.PHP Cross-Site Scripting Vulnerability
PHPNuke INP is prone to a cross-site scripting vulnerability that affects the 'modules.php' script.
The specific version affected is currently unknown.
PHPNuke INP is prone to a cross-site scripting vulnerability that affects the 'modules.php' script.
The specific version affected is currently unknown.
Exploit / POC
PHPNuke INP Modules.PHP Cross-Site Scripting Vulnerability
An exploit is not required.
A proof of concept is available.
An exploit is not required.
A proof of concept is available.
Solution / Fix
PHPNuke INP Modules.PHP Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
PHPNuke INP Modules.PHP Cross-Site Scripting Vulnerability
References:
References:
- PHPNuke INP Homepage (PHPNuke INP)
- PHP-Nuke INP XSS (l2odon)