漏洞标题
N/A
漏洞描述信息
在PHP-Nuke 7.9中,include/mainfile.php文件的解析冲突,稍后允许远程攻击者通过将标签中的">"替换为 "<",绕过去数据净化的正则表达式,但许多浏览器会自动纠正此问题。Note:有人可能认为此漏洞是由于许多浏览器的设计限制所致;如果是这样,那么不应该将这个问题视为PHP-Nuke中的漏洞。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
Interpretation conflict in includes/mainfile.php in PHP-Nuke 7.9 and later allows remote attackers to perform cross-site scripting (XSS) attacks by replacing the ">" in the tag with a "<", which bypasses the regular expressions that sanitize the data, but is automatically corrected by many web browsers. NOTE: it could be argued that this vulnerability is due to a design limitation of many web browsers; if so, then this should not be treated as a vulnerability in PHP-Nuke.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
PHPNuke内容过滤绕过漏洞
漏洞描述信息
PHP-Nuke 7.9及更高版本中的includes/mainfile.php存在解释冲突,远程攻击者可以通过将标签中的">"替换为"<"(可绕过净化数据的正则表达式但会被众多web浏览器自动校正)执行跨站脚本攻击。
CVSS信息
N/A
漏洞类别
跨站脚本