CVE-2006-0800
Title: Postnuke Software Foundation Postnuke Cross-Site Scripting (XSS)
Proof Of Concept
PoC Available for CVE-2006-0800
Vulnerability Summary
CVE-2006-0800: Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" character by some web browsers but bypasses the blacklist protection in (1) the pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput function in pnAntiCracker.php, and (3) the htmltext parameter in an edituser operation to user.php.
Impacted Vendors
Reference Links
AV:N/AC:H/Au:N/C:N/I:P/A:N
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
CVE-2006-0800 Exploits & PoCs (Proof Of Concept)
Vulnerability data updated via NVD.
Vulnerability data or affected products updated.
Vulnerability first announced in NVD.
Attack Vector Matrix
AV:N/AC:H/Au:N/C:N/I:P/A:N
Affected Stack
No specific products linked.