Cross-site scripting vulnerabilities in PostBoard 2.0.1 and earlier allows remote attackers to execute script as other users via (1) an [IMG] tag when BBCode is enabled, or (2) in a topic title.
📦
postnuke
Vendor: postnuke
Actively Exploited
0
CISA KEV List
PoC / Exploits
16
Code Available
Total RCEs
0
Remote Access
Total CVEs
234
Total Indexed
Avg. EPSS
2.42%
Exploit Prob.
Security Vulnerability Index
Page 5 / 24
5.0
CVSS
CVE-2002-0535
Exploit Found
Severity: MEDIUM
2.6
CVSS
Cross-site scripting (XSS) vulnerability in user.php in PostNuke 0.64 allows remote attackers to inject arbitrary web script or HTML via the uname parameter.
Severity: LOW
7.5
CVSS
PHP-Nuke 5.1 stores user and administrator passwords in a base-64 encoded cookie, which could allow remote attackers to gain privileges by stealing or sniffing the cookie and decoding it.
Severity: HIGH
7.5
CVSS
CVE-2001-1460
Exploit Found
SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authentication via the user parameter.
Severity: HIGH