Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-0497 (Nucleus CMS)

BugsAlert Home > CVE-2008-0497 (Nucleus CMS)
 
 

Cross-site scripting (XSS) vulnerability in action.php in Nucleus CMS 3.31 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, which is not quoted when processing PHP_SELF.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0497

Learn more about CVE-2008-0497 (Nucleus CMS)
 
Tags: cve-2008-0497 nucleus cms

Related Items

      CVE-2007-6084 (clone_script)

      CVE-2008-3184 (vbulletin)

      WORM_AUTORUN.AQV

      Mandriva: Updated wireshark packages fix denial of service

      Securing Your Network With PacketFence

      Microsoft Security Advisory (927892): Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution - 11/14/2006

      Joomla! mediaslide Component "albumnum" SQL Injection

 

Pixel