← Back

CVE-2006-4480

nvd nist
Published: Aug 31, 2006Modified: Apr 16, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Incomplete blacklist vulnerability in the nk_CSS function in nuked.php in Nuked-Klan 1.7 SP4.3 allows remote attackers to bypass anti-XSS features and inject arbitrary web script or HTML via JavaScript in an attribute value that is not in the blacklist, as demonstrated using the STYLE attribute of a B element.

Affected (1)

1 product
Nuked Klan
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.7_sp4.3

References (4)

Timeline

No history available yet.