Total vulnerabilities in the database
Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers to inject arbitrary web script or HTML via the user_avatar parameter.
Software | From | Fixed in |
---|---|---|
francisco_burzi / php-nuke | 5.3.1 | 5.3.1.x |
francisco_burzi / php-nuke | 5.1 | 5.1.x |
francisco_burzi / php-nuke | 5.0 | 5.0.x |
francisco_burzi / php-nuke | 5.5 | 5.5.x |
francisco_burzi / php-nuke | 5.4 | 5.4.x |
francisco_burzi / php-nuke | 5.2a | 5.2a.x |
francisco_burzi / php-nuke | 5.0.1 | 5.0.1.x |
francisco_burzi / php-nuke | 5.2 | 5.2.x |
francisco_burzi / php-nuke | 5.6 | 5.6.x |
francisco_burzi / php-nuke | 6.0 | 6.0.x |