CVE-2006-0800
Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" character by some web browsers but bypasses the…
Does this matter?
Lower severity and a low EPSS score (2.18%). Track it; it rarely justifies an emergency change on its own.
Description
Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" character by some web browsers but bypasses the blacklist protection in (1) the pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput function in pnAntiCracker.php, and (3) the htmltext parameter in an edituser operation to user.php.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
- EPSS
- 2.18% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- postnuke software foundation/postnuke
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0469.html
- http://news.postnuke.com/index.php?name=News&file=article&sid=2754Patch
- http://secunia.com/advisories/18937Patch, Vendor Advisory
- http://securityreason.com/securityalert/454
- http://www.securityfocus.com/bid/16752Exploit, Patch
- http://www.vupen.com/english/advisories/2006/0673Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24823
- http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0469.html
- http://news.postnuke.com/index.php?name=News&file=article&sid=2754Patch
- http://secunia.com/advisories/18937Patch, Vendor Advisory
- http://securityreason.com/securityalert/454
- http://www.securityfocus.com/bid/16752Exploit, Patch
- http://www.vupen.com/english/advisories/2006/0673Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24823
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.