Description
|
|
Several vulnerabilities were identified in PhpNuke, which could be exploited by attackers to conduct Cross Site Scripting attacks. The first flaw resides in the "db/db.php", "mainfile.php", "modules/Downloads/index.php", and "modules/Web_Links/index.php" files, which may be exploited to determine the installation path. The second vulnerability resides in the "modules/Downloads/index.php" and "modules/Web_Links/index.php" files, when handling specially crafted "newlinkshowdays" and "newdownloadshowdays" parameters, which may be exploited to conduct Cross Site Scripting attacks.
|