Security Advisory

CVE-2006-4480

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2006-08-31 21:00:00
Last updated 2024-08-07 19:14:46
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Incomplete blacklist vulnerability in the nk_CSS function in nuked.php in Nuked-Klan 1.7 SP4.3 allows remote attackers to bypass anti-XSS features and inject arbitrary web script or HTML via JavaScript in an attribute value that is not in the blacklist, as demonstrated using the STYLE attribute of a B element.