Cross-site scripting (XSS) vulnerability in GBook for Php-Nuke 1.0 allows remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) name, (2) email, (3) city, and (4) message, which do not use the and tags, which are filtered by PHP-Nuke.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gbook | Martin_bauer | * | * |
Gbook | Martin_bauer | 1.4 (including) | 1.4 (including) |