MEDIUM
Incomplete blacklist vulnerability in the nk_CSS function in nuked.php in Nuked-Klan 1.7 SP4.3 allows remote attackers to bypass anti-XSS features and inject arbitrary web script or HTML via JavaScript in an attribute value that is not in the blacklist, as demonstrated using the STYLE attribute of a B element
Published Aug 31, 2006
4.3
MEDIUMCVSS 2.0
EPSS 1.28%
Description
Affected products
Remediation
References (2)
Change history (0)
No recorded changes yet.