Exploitation Summary
EIP tracks 1 public exploit for CVE-2005-3368. PoCs published by bhfh01.
AI-analyzed exploit summary This HTML injection PoC demonstrates a stored XSS vulnerability in the Search Enhanced module by injecting a malicious script via the 'query' parameter. The script is automatically submitted via JavaScript, executing arbitrary code in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in the Search_Enhanced module in PHP-Nuke 7.9 allows remote attackers to inject arbitrary web script or HTML via the query parameter.
Exploits (1)
This HTML injection PoC demonstrates a stored XSS vulnerability in the Search Enhanced module by injecting a malicious script via the 'query' parameter. The script is automatically submitted via JavaScript, executing arbitrary code in the context of the affected site.