CVE Vulnerabilities

CVE-2006-6920

Published: Jan 11, 2007 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Cross-site scripting (XSS) vulnerability in Nucleus before 3.24 allows remote attackers to inject arbitrary web script or HTML via unknown vectors, possibly involving (1) lib/ADMIN.php and (2) lib/SKIN.php.

Affected Software

Name Vendor Start Version End Version
Nucleus_cms Nucleus_cms 3.0_rc 3.0_rc
Nucleus_cms Nucleus_cms 3.01 3.01
Nucleus_cms Nucleus_cms 3.2 3.2
Nucleus_cms Nucleus_cms 3.22 3.22
Nucleus_cms Nucleus_cms 3.23 3.23
Nucleus_cms Nucleus_cms 3.21 3.21
Nucleus_cms Nucleus_cms 3.0 3.0
Nucleus_cms Nucleus_cms 3.1 3.1

References