CVE-2011-1481

Multiple cross-site scripting (XSS) vulnerabilities in Francisco Burzi PHP-Nuke 8.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sender_name or (2) sender_email parameter in a Feedback action to modules.php.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
VendorProductVersion
phpnukephp-nuke
𝑥
≤ 8.0
phpnukephp-nuke
5.0
phpnukephp-nuke
5.0.1
phpnukephp-nuke
5.1
phpnukephp-nuke
5.2
phpnukephp-nuke
5.3
phpnukephp-nuke
5.3.1
phpnukephp-nuke
5.4
phpnukephp-nuke
5.5
phpnukephp-nuke
5.6
phpnukephp-nuke
6.0
phpnukephp-nuke
6.5
phpnukephp-nuke
6.6
phpnukephp-nuke
6.7
phpnukephp-nuke
6.8
phpnukephp-nuke
6.9
phpnukephp-nuke
7.0
phpnukephp-nuke
7.1
phpnukephp-nuke
7.2
phpnukephp-nuke
7.3
phpnukephp-nuke
7.4
phpnukephp-nuke
7.5
phpnukephp-nuke
7.6
phpnukephp-nuke
7.7
phpnukephp-nuke
7.8
phpnukephp-nuke
7.9
𝑥
= Vulnerable software versions