|
|
Info |
Last Modified |
| 8 months ago |
|
|
|
|
|
This Entry needs help! It is only 0% Complete. Click the edit link above to add more information.
Contributing is fast and easy, and benefits the entire security community.
|
Description |
(Description Provided by CVE) : Incomplete blacklist vulnerability in the nk_CSS function in nuked.php in Nuked-Klan 1.7 SP4.3 allows remote attackers to bypass anti-XSS features and inject arbitrary web script or HTML via JavaScript in an attribute value that is not in the blacklist, as demonstrated using the STYLE attribute of a B element.
|
|
Classification |
Unknown or Incomplete
|
|
Products |
Unknown or Incomplete
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|