Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Pyvnc2Swf

#50965de 53,622
4.3CVSS total
Vulnerabilidades · 1
PT-2007-2909
4.3
2007-03-20
Php Nuke · Php-Nuke · CVE-2007-1519
**Name of the Vulnerable Software and Affected Versions** PHP-Nuke versions 8.0 and earlier **Description** A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search operation in the Downloads module. **Recommendations** For PHP-Nuke versions 8.0 and earlier, as a temporary workaround, consider restricting access to the Downloads module until a patch is available. Avoid using the query parameter in search operations within the Downloads module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.