Lucene search

K
freebsdFreeBSD7E580822-8CD8-11D9-8C81-000A95BC6FAE
HistoryFeb 28, 2005 - 12:00 a.m.

postnuke -- cross-site scripting (XSS) vulnerabilities

2005-02-2800:00:00
vuxml.freebsd.org
14

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

58.8%

A cross-site scripting vulnerability is present in the
PostNuke PHP content management system. By passing data
injected through exploitable errors in input validation, an
attacker can insert code which will run on the machine of
anybody viewing the page. It is feasible that this attack
could be used to retrieve session information from cookies,
thereby allowing the attacker to gain administrative access
to the CMS.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchpostnuke< 0.760UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

58.8%

Related for 7E580822-8CD8-11D9-8C81-000A95BC6FAE