CVE detail
CVE-2005-4260 — CVE-2005-4260
Published 2005-12-15 · Modified 2026-06-16 · Vendor francisco_burzi · Product php-nuke · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0211
EPSS probability
exploitation probability, 30d
80.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Interpretation conflict in includes/mainfile.php in PHP-Nuke 7.9 and later allows remote attackers to perform cross-site scripting (XSS) attacks by replacing the ">" in the tag with a "<", which bypasses the regular expressions that sanitize the data, but is automatically corrected by many web browsers. NOTE: it could be argued that this vulnerability is due to a design limitation of many web browsers; if so, then this should not be treated as a vulnerability in PHP-Nuke.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References