CVE-2006-0800
Last modified
CVE-2006-0800 is a vulnerability of currently unknown severity. Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" character by some web browsers but bypasses the blacklist protection in (1) the pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput function in pnAntiCracker.php, and (3) the htmltext parameter in an edituser operation to user.php.. EPSS estimates a 2.13% chance of exploitation in the next 30 days.
Description
Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" character by some web browsers but bypasses the blacklist protection in (1) the pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput function in pnAntiCracker.php, and (3) the htmltext parameter in an edituser operation to user.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Postnuke Software Foundation | Postnuke | 0.7 |
| Postnuke Software Foundation | Postnuke | 0.62 |
| Postnuke Software Foundation | Postnuke | 0.63 |
| Postnuke Software Foundation | Postnuke | 0.64 |
| Postnuke Software Foundation | Postnuke | 0.70 |
| Postnuke Software Foundation | Postnuke | 0.71 |
| Postnuke Software Foundation | Postnuke | 0.72 |
| Postnuke Software Foundation | Postnuke | 0.73 |
| Postnuke Software Foundation | Postnuke | 0.74 |
| Postnuke Software Foundation | Postnuke | 0.75 |
| Postnuke Software Foundation | Postnuke | 0.75_rc3 |
| Postnuke Software Foundation | Postnuke | 0.76_rc4 |
| Postnuke Software Foundation | Postnuke | 0.76_rc4a |
| Postnuke Software Foundation | Postnuke | 0.76_rc4b |
| Postnuke Software Foundation | Postnuke | 0.703 |
| Postnuke Software Foundation | Postnuke | 0.721 |
| Postnuke Software Foundation | Postnuke | 0.726.3 |
| Postnuke Software Foundation | Postnuke | 0.761 |
| Postnuke Software Foundation | Postnuke | 0.761a |
References
- http://secunia.com/advisories/18937Patch, Vendor Advisory
- http://www.securityfocus.com/bid/16752Exploit, Patch
- http://www.vupen.com/english/advisories/2006/0673Vendor Advisory
- http://secunia.com/advisories/18937Patch, Vendor Advisory
- http://www.securityfocus.com/bid/16752Exploit, Patch
- http://www.vupen.com/english/advisories/2006/0673Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-0800?
How severe is CVE-2006-0800?
How do I fix CVE-2006-0800?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-0794help.php in V-webmail 1.6.2 allows remote attackers to obtai…
- CVE-2006-0795Absolute path traversal vulnerability in convert.cgi in Quir…
- CVE-2006-0796Cross-site scripting (XSS) vulnerability in default.php in C…
- CVE-2006-0797Nokia N70 cell phone allows remote attackers to cause a deni…
- CVE-2006-0798Multiple directory traversal vulnerabilities in the IMAP ser…
- CVE-2006-0799Microsoft Internet Explorer allows remote attackers to spoof…
- CVE-2006-0801SQL injection vulnerability in the NS-Languages module for P…
- CVE-2006-0802Cross-site scripting (XSS) vulnerability in the NS-Languages…
- CVE-2006-0803The signature verification functionality in the YaST Online …
- CVE-2006-0804Off-by-one error in TIN 1.8.0 and earlier might allow attack…
- CVE-2006-0805The CAPTCHA functionality in php-Nuke 6.0 through 7.9 uses f…
- CVE-2006-0806Multiple cross-site scripting (XSS) vulnerabilities in ADOdb…
Are you affected by CVE-2006-0800?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
