← Back

CVE-2005-4260

nvd nist
Published: Dec 15, 2005Modified: Apr 16, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Interpretation conflict in includes/mainfile.php in PHP-Nuke 7.9 and later allows remote attackers to perform cross-site scripting (XSS) attacks by replacing the ">" in the tag with a "<", which bypasses the regular expressions that sanitize the data, but is automatically corrected by many web browsers. NOTE: it could be argued that this vulnerability is due to a design limitation of many web browsers; if so, then this should not be treated as a vulnerability in PHP-Nuke.

Affected (8)

Php Nuke
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Francisco Burzi
Version 7.0
Version 7.1
Version 7.2
Version 7.3
Version 7.6
Version 7.7
Version 7.8
Version 7.9

References (6)

Timeline

No history available yet.