CVE-2002-1995

phptonuke.php - Cross-Site Scripting via filnavn Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-1995. PoCs published by frog.

AI-analyzed exploit summary This is a writeup describing a reflected XSS vulnerability in phptonuke.php, a PHPNuke AddOn script. The vulnerability allows an attacker to inject arbitrary JavaScript code via the 'filnavn' parameter, which executes in the context of the victim's browser session.

Description

Cross-site scripting (XSS) vulnerability in phptonuke.php for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the filnavn parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by frog · textwebappsphp
https://www.exploit-db.com/exploits/21206

This is a writeup describing a reflected XSS vulnerability in phptonuke.php, a PHPNuke AddOn script. The vulnerability allows an attacker to inject arbitrary JavaScript code via the 'filnavn' parameter, which executes in the context of the victim's browser session.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: phptonuke.php (PHPNuke AddOn)
No auth needed
Prerequisites: Victim must click a crafted link
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3807
Exploit mailing-list x_refsource_vuln-dev
http://archives.neohapsis.com/archives/vuln-dev/2002-q1/0048.html
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/7837.php

Scores

EPSS 0.0354
EPSS Percentile 87.8%

Details

Status published
Products (1)
lebios/phptonuke.php 1.0
Published Dec 31, 2002
Tracked Since Feb 18, 2026