← Back

CVE-2005-1023

nvd nist
Published: May 2, 2005Modified: Apr 16, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) min parameter to the Search module, (2) the categories parameter to the FAQ module, or (3) the ltr parameter to the Encyclopedia module. NOTE: the bid parameter issue in banners.php is already an item in CVE-2005-1000.

Affected (18)

Php Nuke
Configuration A
18 vulnerable
Vulnerable SoftwareAffected Versions
Francisco Burzi
Version 6.0
Version 6.5
Version 6.5_beta1
Version 6.5_final
Version 6.5_rc1
Version 6.5_rc2
Version 6.5_rc3
Version 6.6
Version 6.7
Version 6.9
Version 7.0
Version 7.0_final
Version 7.1
Version 7.2
Version 7.3
Version 7.4
Version 7.5
Version 7.6

Timeline

No history available yet.