CVE-2005-1000
Last modified
CVE-2005-1000 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the bid parameter to the EmailStats op in banners.pgp, (2) the ratenum parameter in the TopRated and MostPopular actions in the Web_Links module, (3) the ttitle parameter in the viewlinkdetails, viewlinkeditorial, viewlinkcomments, and ratelink actions in the Web_Links module, or (4) the username parameter in the Your_Account module.. EPSS estimates a 1.76% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the bid parameter to the EmailStats op in banners.pgp, (2) the ratenum parameter in the TopRated and MostPopular actions in the Web_Links module, (3) the ttitle parameter in the viewlinkdetails, viewlinkeditorial, viewlinkcomments, and ratelink actions in the Web_Links module, or (4) the username parameter in the Your_Account module.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Francisco Burzi | Php-Nuke | 7.6 |
References
- http://archives.neohapsis.com/archives/bugtraq/2005-04/0037.htmlExploit, Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2005-04/0037.htmlExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-1000?
How severe is CVE-2005-1000?
How do I fix CVE-2005-1000?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-0994Multiple SQL injection vulnerabilities in ProductCart 2.7 al…
- CVE-2005-0995Multiple cross-site scripting (XSS) vulnerabilities in Produ…
- CVE-2005-0996Multiple SQL injection vulnerabilities in the Downloads modu…
- CVE-2005-0997Multiple SQL injection vulnerabilities in the Web_Links modu…
- CVE-2005-0998The Web_Links module for PHP-Nuke 7.6 allows remote attacker…
- CVE-2005-0999SQL injection vulnerability in the Top module for PHP-Nuke 6…
- CVE-2005-10001A vulnerability was found in Netegrity SiteMinder up to 4.5.…6.1
- CVE-2005-10002A vulnerability, which was classified as critical, was found…9.8
- CVE-2005-10003A vulnerability classified as critical has been found in mik…9.8
- CVE-2005-10004Cacti versions prior to 0.8.6-d contain a remote command exe…8.8
- CVE-2005-1001PHP-Nuke 7.6 allows remote attackers to obtain sensitive inf…
- CVE-2005-1002logwebftbs2000.exe in Logics Software File Transfer (LOG-FT)…
Are you affected by CVE-2005-1000?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
