Multiple cross-site scripting (XSS) vulnerabilities in the Search Module in PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via a trailing < instead of a > in (1) the onerror attribute of an IMG element, (2) the onload attribute of an IFRAME element, or (3) redirect users to other sites via the META tag.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Php-nuke | Phpnuke | 7.0 (including) | 7.0 (including) |
Php-nuke | Phpnuke | 7.1 (including) | 7.1 (including) |
Php-nuke | Phpnuke | 7.2 (including) | 7.2 (including) |
Php-nuke | Phpnuke | 7.3 (including) | 7.3 (including) |
Php-nuke | Phpnuke | 7.4 (including) | 7.4 (including) |
Php-nuke | Phpnuke | 7.5 (including) | 7.5 (including) |
Php-nuke | Phpnuke | 7.6 (including) | 7.6 (including) |
Php-nuke | Phpnuke | 7.7 (including) | 7.7 (including) |
Php-nuke | Phpnuke | 7.8 (including) | 7.8 (including) |
Php-nuke | Phpnuke | 7.9 (including) | 7.9 (including) |
Php-nuke | Phpnuke | 8.0 (including) | 8.0 (including) |