CVE detail
CVE-2006-0800 — CVE-2006-0800
Published 2006-02-20 · Modified 2026-06-16 · Vendor postnuke_software_foundation · Product postnuke · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0218
EPSS probability
exploitation probability, 30d
81.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" character by some web browsers but bypasses the blacklist protection in (1) the pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput function in pnAntiCracker.php, and (3) the htmltext parameter in an edituser operation to user.php.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References