CVE

Id
13745  
CVE No.
CVE-2005-2539  
Status
Candidate  
Description
Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitrary web script or HTML via the (1) bodycolor, (2) backimage, (3) theme, or (4) logo parameter to structure.php, (5) admin, (6) admin_mail, or (7) back parameter to footer.php, or (8) the message body in a news post.  
Phase
Assigned (20050810)  
Votes
None (candidate not yet proposed)  
Comments