CVE-2006-0800
Last modified
CVE-2006-0800 is a vulnerability of currently unknown severity. Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" character by some web browsers but bypasses the blacklist protection in (1) the pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput function in pnAntiCracker.php, and (3) the htmltext parameter in an edituser operation to user.php.. EPSS estimates a 2.13% chance of exploitation in the next 30 days.
Description
Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" character by some web browsers but bypasses the blacklist protection in (1) the pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput function in pnAntiCracker.php, and (3) the htmltext parameter in an edituser operation to user.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Postnuke Software Foundation | Postnuke | 0.7 |
| Postnuke Software Foundation | Postnuke | 0.62 |
| Postnuke Software Foundation | Postnuke | 0.63 |
| Postnuke Software Foundation | Postnuke | 0.64 |
| Postnuke Software Foundation | Postnuke | 0.70 |
| Postnuke Software Foundation | Postnuke | 0.71 |
| Postnuke Software Foundation | Postnuke | 0.72 |
| Postnuke Software Foundation | Postnuke | 0.73 |
| Postnuke Software Foundation | Postnuke | 0.74 |
| Postnuke Software Foundation | Postnuke | 0.75 |
| Postnuke Software Foundation | Postnuke | 0.75_rc3 |
| Postnuke Software Foundation | Postnuke | 0.76_rc4 |
| Postnuke Software Foundation | Postnuke | 0.76_rc4a |
| Postnuke Software Foundation | Postnuke | 0.76_rc4b |
| Postnuke Software Foundation | Postnuke | 0.703 |
| Postnuke Software Foundation | Postnuke | 0.721 |
| Postnuke Software Foundation | Postnuke | 0.726.3 |
| Postnuke Software Foundation | Postnuke | 0.761 |
| Postnuke Software Foundation | Postnuke | 0.761a |
References
- http://secunia.com/advisories/18937Patch, Vendor Advisory
- http://www.securityfocus.com/bid/16752Exploit, Patch
- http://www.vupen.com/english/advisories/2006/0673Vendor Advisory
- http://secunia.com/advisories/18937Patch, Vendor Advisory
- http://www.securityfocus.com/bid/16752Exploit, Patch
- http://www.vupen.com/english/advisories/2006/0673Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-0800?
How severe is CVE-2006-0800?
How do I fix CVE-2006-0800?
Are you affected by CVE-2006-0800?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
