IndyNews HTML Injection Vulnerability...

- AV AC AU C I A
发布: 2003-02-14
修订: 2025-04-13

A vulnerability has been discovered in the IndyNews module available for PHP-Nuke. Due to insufficient sanitization of some HTML tags it is possible to embed HTML code within the 'alt' tags of a news article. When the news article is viewed by an unsuspecting user the embedded code will be executed within the context of the site visited. The precise technical details regarding this vulnerability are currently unknown. This BID will be updated accordingly as more information is made available.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息