CVE-2005-1027
PHP-Nuke 6.x-7.6 - Cross-Site Scripting via Username, Avatarcategory, or Downloads Lid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-1027. PoCs published by [email protected].
AI-analyzed exploit summary This is a writeup describing a cross-site scripting (XSS) vulnerability in PHP-Nuke's 'Downloads' module. It explains how an attacker can craft a malicious URI to execute arbitrary script code in the context of the victim's browser.
Description
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x through 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in the Your_Account module, (2) avatarcategory parameter in the Your_Account module, or (3) lid parameter in the Downloads module.
Exploits (1)
This is a writeup describing a cross-site scripting (XSS) vulnerability in PHP-Nuke's 'Downloads' module. It explains how an attacker can craft a malicious URI to execute arbitrary script code in the context of the victim's browser.