Php Nuke · Php-Nuke · CVE-2008-1348
**Name of the Vulnerable Software and Affected Versions**
eWebsite eWeather (Weather) module for PHP-Nuke (affected versions not specified)
**Description**
The issue is related to a cross-site scripting (XSS) vulnerability. This vulnerability allows remote attackers to inject arbitrary web script or HTML via the `chart` parameter to "modules.php".
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.