ID

VAR-200512-0217


CVE

CVE-2005-4260


TITLE

PHPNuke Content Filtering Bypass Vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200512-316

DESCRIPTION

Interpretation conflict in includes/mainfile.php in PHP-Nuke 7.9 and later allows remote attackers to perform cross-site scripting (XSS) attacks by replacing the ">" in the tag with a "<", which bypasses the regular expressions that sanitize the data, but is automatically corrected by many web browsers. NOTE: it could be argued that this vulnerability is due to a design limitation of many web browsers; if so, then this should not be treated as a vulnerability in PHP-Nuke. PHPNuke is prone to a content filtering bypass vulnerability. This issue can allow an attacker to bypass content filters and potentially carry out cross-site scripting, HTML injection and other attacks. PHPNuke 7.9 and prior versions are reported to be vulnerable

Trust: 1.26

sources: NVD: CVE-2005-4260 // BID: 15855 // VULHUB: VHN-15468

AFFECTED PRODUCTS

vendor:francisco burzimodel:php-nukescope:eqversion:7.7

Trust: 1.6

vendor:francisco burzimodel:php-nukescope:eqversion:7.0

Trust: 1.6

vendor:francisco burzimodel:php-nukescope:eqversion:7.2

Trust: 1.6

vendor:francisco burzimodel:php-nukescope:eqversion:7.1

Trust: 1.6

vendor:francisco burzimodel:php-nukescope:eqversion:7.3

Trust: 1.6

vendor:francisco burzimodel:php-nukescope:eqversion:7.6

Trust: 1.6

vendor:francisco burzimodel:php-nukescope:eqversion:7.8

Trust: 1.6

vendor:francisco burzimodel:php-nukescope:eqversion:7.9

Trust: 1.6

vendor:franciscomodel:burzi php-nukescope:eqversion:7.1

Trust: 0.3

vendor:franciscomodel:burzi php-nukescope:eqversion:7.2

Trust: 0.3

vendor:franciscomodel:burzi php-nukescope:eqversion:7.0

Trust: 0.3

vendor:franciscomodel:burzi php-nukescope:eqversion:7.6

Trust: 0.3

vendor:franciscomodel:burzi php-nukescope:eqversion:7.7

Trust: 0.3

vendor:franciscomodel:burzi php-nukescope:eqversion:7.3

Trust: 0.3

vendor:franciscomodel:burzi php-nukescope:eqversion:7.9

Trust: 0.3

vendor:franciscomodel:burzi php-nukescope:eqversion:7.8

Trust: 0.3

sources: BID: 15855 // CNNVD: CNNVD-200512-316 // NVD: CVE-2005-4260

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2005-4260
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200512-316
value: MEDIUM

Trust: 0.6

VULHUB: VHN-15468
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2005-4260
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-15468
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-15468 // CNNVD: CNNVD-200512-316 // NVD: CVE-2005-4260

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2005-4260

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200512-316

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-200512-316

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-15468

EXTERNAL IDS

db:BIDid:15855

Trust: 2.0

db:NVDid:CVE-2005-4260

Trust: 1.7

db:CNNVDid:CNNVD-200512-316

Trust: 0.7

db:BUGTRAQid:20051214 BYPASS XSS FILTER IN PHPNUKE 7.9=>X

Trust: 0.6

db:BUGTRAQid:20051220 RE: XSS BYPASS IN PHPNUKE - FIX ?

Trust: 0.6

db:EXPLOIT-DBid:26817

Trust: 0.1

db:VULHUBid:VHN-15468

Trust: 0.1

sources: VULHUB: VHN-15468 // BID: 15855 // CNNVD: CNNVD-200512-316 // NVD: CVE-2005-4260

REFERENCES

url:http://www.securityfocus.com/bid/15855

Trust: 1.7

url:http://www.securityfocus.com/archive/1/419496/100/0/threaded

Trust: 1.1

url:http://www.securityfocus.com/archive/1/419991/100/0/threaded

Trust: 1.1

url:http://www.securityfocus.com/archive/1/archive/1/419991/100/0/threaded

Trust: 0.6

url:http://www.securityfocus.com/archive/1/archive/1/419496/100/0/threaded

Trust: 0.6

url:http://www.irannuke.com/

Trust: 0.3

sources: VULHUB: VHN-15468 // BID: 15855 // CNNVD: CNNVD-200512-316 // NVD: CVE-2005-4260

CREDITS

Discovered by Maksymilian Arciemowicz <max@jestsuper.pl>.

Trust: 0.9

sources: BID: 15855 // CNNVD: CNNVD-200512-316

SOURCES

db:VULHUBid:VHN-15468
db:BIDid:15855
db:CNNVDid:CNNVD-200512-316
db:NVDid:CVE-2005-4260

LAST UPDATE DATE

2024-08-14T15:09:46.186000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-15468date:2018-10-19T00:00:00
db:BIDid:15855date:2005-12-14T00:00:00
db:CNNVDid:CNNVD-200512-316date:2006-06-09T00:00:00
db:NVDid:CVE-2005-4260date:2018-10-19T15:40:42.473

SOURCES RELEASE DATE

db:VULHUBid:VHN-15468date:2005-12-15T00:00:00
db:BIDid:15855date:2005-12-14T00:00:00
db:CNNVDid:CNNVD-200512-316date:2005-12-15T00:00:00
db:NVDid:CVE-2005-4260date:2005-12-15T11:03:00