CVE-2005-1027
PHP-Nuke <7.6 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x through 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in the Your_Account module, (2) avatarcategory parameter in the Your_Account module, or (3) lid parameter in the Downloads module.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
https://www.exploit-db.com/exploits/25341
References (4)
Scores
EPSS
0.0004
EPSS Percentile
12.7%
Details
Status
published
Products (18)
francisco_burzi/php-nuke
6.0
francisco_burzi/php-nuke
6.5
francisco_burzi/php-nuke
6.5_beta1
francisco_burzi/php-nuke
6.5_final
francisco_burzi/php-nuke
6.5_rc1
francisco_burzi/php-nuke
6.5_rc2
francisco_burzi/php-nuke
6.5_rc3
francisco_burzi/php-nuke
6.6
francisco_burzi/php-nuke
6.7
francisco_burzi/php-nuke
6.9
... and 8 more
Published
May 02, 2005
Tracked Since
Feb 18, 2026