CVE-2011-1481

PHP-Nuke <8.0 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in Francisco Burzi PHP-Nuke 8.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sender_name or (2) sender_email parameter in a Feedback action to modules.php.

Scores

EPSS 0.0025
EPSS Percentile 48.5%

Classification

CWE
CWE-79
Status published

Affected Products (27)

phpnuke/php-nuke < 8.0
phpnuke/php-nuke
phpnuke/php-nuke
phpnuke/php-nuke
phpnuke/php-nuke
phpnuke/php-nuke
phpnuke/php-nuke
phpnuke/php-nuke
phpnuke/php-nuke
phpnuke/php-nuke
phpnuke/php-nuke
phpnuke/php-nuke
phpnuke/php-nuke
phpnuke/php-nuke
phpnuke/php-nuke
... and 12 more

Timeline

Published Jun 21, 2011
Tracked Since Feb 18, 2026