Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Pyvnc2Swf

#52030of 53,608
4.3Total CVSS
Vulnerabilities · 1
PT-2007-2909
4.3
2007-03-20
Php Nuke · Php-Nuke · CVE-2007-1519
**Name of the Vulnerable Software and Affected Versions** PHP-Nuke versions 8.0 and earlier **Description** A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search operation in the Downloads module. **Recommendations** For PHP-Nuke versions 8.0 and earlier, as a temporary workaround, consider restricting access to the Downloads module until a patch is available. Avoid using the query parameter in search operations within the Downloads module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.