CVE-2006-0800
Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing...
- Published
- Feb 20, 2006
- Updated
- Aug 7, 2024
- Assigning CNA
- mitre
- Evidence observed
- Feb 21, 2006
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:H/Au:N/C:N/I:P/A:NLow · next 30 days
- Percentile
- 81.3%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" character by some web browsers but bypasses the blacklist protection in (1) the pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput function in pnAntiCracker.php, and (3) the htmltext parameter in an edituser operation to user.php.
Sources
1Maksymilian Arciemowicz · php · Feb 21, 2006
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.