PT-2007-3764 · Nukeedit · Nukedit

Published

2007-05-02

·

Updated

2017-07-29

·

CVE-2007-2432

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions nukedit version 4.9.7b
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the terms parameter in the "utilities/search.asp" page.
Recommendations For nukedit version 4.9.7b, consider restricting access to the utilities/search.asp page or avoid using the terms parameter until a fix is available. As a temporary workaround, validate and sanitize all user input to the terms parameter to prevent malicious script injection.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2432

Affected Products

Nukedit