CVE-2006-0800

Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" character by some web browsers but bypasses the blacklist protection in (1) the pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput function in pnAntiCracker.php, and (3) the htmltext parameter in an edituser operation to user.php.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:postnuke_software_foundation:postnuke:0.7:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.62:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.63:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.64:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.70:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.71:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.72:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.73:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.74:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.75:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.75_rc3:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.76_rc4:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.76_rc4a:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.76_rc4b:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.703:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.721:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.726.3:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.761:*:*:*:*:*:*:*
cpe:2.3:a:postnuke_software_foundation:postnuke:0.761a:*:*:*:*:*:*:*

History

No history.

Information

Published : 2006-02-20 22:02

Updated : 2024-02-04 16:52


NVD link : CVE-2006-0800

Mitre link : CVE-2006-0800

CVE.ORG link : CVE-2006-0800


JSON object : View

Products Affected

postnuke_software_foundation

  • postnuke
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')