CVE-2005-0616

Properties

Published:
27.02.2005
Updated:
20.10.2005
Patch available:
Severity:
Low
  • CVSS vector:
    (AV:R/AC:L/Au:NR/C:N/I:C/A:N/B:N) Approximated
    Product:
    PostNuke Development Team: PostNuke Phoenix
    PostNuke Development Team: PostNuke Phoenix

    Vulnerability description

    Multiple cross-site scripting (XSS) vulnerabilities in the Download module for PostNuke 0.750 and 0.760-RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) Program name, (2) File link, (3) Author name (4) Author e-mail address, (5) File size, (6) Version, or (7) Home page variables.

    References:

    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=110962768300373&w=2
    CONFIRM: http://news.postnuke.com/Article2669.html
    MISC: http://securitytracker.com/id?1013324
    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=110962768300373&w=2