← Voltar para CVEs
CVE-2006-0802
N/ADescricao
Cross-site scripting (XSS) vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is enabled, allows remote attackers to inject arbitrary web script or HTML via the language parameter in a missing or translation operation.
Detalhes CVE
Pontuacao CVSS v3.1N/A
Publicado2/20/2006
Ultima modificacao4/16/2026
Fontenvd
Avistamentos honeypot0
Produtos afetados
postnuke_software_foundation:postnuke
Referencias
http://secunia.com/advisories/18937(cve@mitre.org)
http://securityreason.com/securityalert/454(cve@mitre.org)
http://www.securityfocus.com/bid/16752(cve@mitre.org)
http://www.vupen.com/english/advisories/2006/0673(cve@mitre.org)
https://exchange.xforce.ibmcloud.com/vulnerabilities/24823(cve@mitre.org)
http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0469.html(af854a3a-2127-422b-91ae-364da2661108)
http://news.postnuke.com/index.php?name=News&file=article&sid=2754(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/18937(af854a3a-2127-422b-91ae-364da2661108)
http://securityreason.com/securityalert/454(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/16752(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2006/0673(af854a3a-2127-422b-91ae-364da2661108)
https://exchange.xforce.ibmcloud.com/vulnerabilities/24823(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.