PT-2007-3764 · Nukeedit · Nukedit
Published
2007-05-02
·
Updated
2017-07-29
·
CVE-2007-2432
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
nukedit version 4.9.7b
Description
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the
terms parameter in the "utilities/search.asp" page.Recommendations
For nukedit version 4.9.7b, consider restricting access to the
utilities/search.asp page or avoid using the terms parameter until a fix is available. As a temporary workaround, validate and sanitize all user input to the terms parameter to prevent malicious script injection.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nukedit