Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-0800

Опубликовано: 20 фев. 2006
Источник: nvd
CVSS2: 2.6
EPSS Низкий

Описание

Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" character by some web browsers but bypasses the blacklist protection in (1) the pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput function in pnAntiCracker.php, and (3) the htmltext parameter in an edituser operation to user.php.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:postnuke_software_foundation:postnuke:0.7:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.62:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.63:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.64:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.70:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.71:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.72:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.73:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.74:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.75:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.75_rc3:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.76_rc4:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.76_rc4a:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.76_rc4b:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.703:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.721:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.726.3:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.761:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.761a:*:*:*:*:*:*:*

EPSS

Процентиль: 92%
0.07475
Низкий

2.6 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

github
почти 4 года назад

Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" character by some web browsers but bypasses the blacklist protection in (1) the pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput function in pnAntiCracker.php, and (3) the htmltext parameter in an edituser operation to user.php.

EPSS

Процентиль: 92%
0.07475
Низкий

2.6 Low

CVSS2

Дефекты

CWE-79