PHP-Nuke 6.0 Multiple Cross Site...

- AV AC AU C I A
发布: 2002-12-16
修订: 2025-04-13

It has been discovered that multiple PHP scripts used by PHP-Nuke are vulnerable to cross-sitescripting attacks. Due to insufficient sanitization of web requests it is possible for script code to be embedded in PHP script requests. By constructing a malicious link which exploits one of these vulnerabilities, it may be possible to execute arbitrary code within the context of a website visited by an unsuspecting user. This may allow a remote attacker to steal cookie-based authentication credentials, which could be used at a later time to hijack a users web session.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息