Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the bid parameter to the EmailStats op in banners.pgp, (2) the ratenum parameter in the TopRated and MostPopular actions in the Web_Links module, (3) the ttitle parameter in the viewlinkdetails, viewlinkeditorial, viewlinkcomments, and ratelink actions in the Web_Links module, or (4) the username parameter in the Your_Account module.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP-Nuke Your_Account用户名跨站脚本攻击漏洞
Vulnerability Description
PHP-Nuke 7.6存在多个跨站脚本攻击(XSS)漏洞,远程攻击者可以通过1)传给banners.pgp内的EmailStats选项的bid参数,(2)Web_Links模块内TopRated和MostPopular操作的ratenum参数,(3)Web_Links模块内viewlinkdetails、viewlinkeditorial、viewlinkcomments和ratelink操作的ttitle参数,或者(4)Your_Account模块内的用户名参数,注入任意Web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A