peter bassill · operator
$ cve CVE-2001-1524 JSON

CVE-2001-1524 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 2% (pctl 80)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) uname parameter in user.php, (2) ttitle, letter and file parameters in modules.php, (3) subject, story and storyext parameters in submit.php, (4) upload parameter in admin.php and (5) fname parameter in friend.php.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS2.01% — more likely to be exploited than 80% of all CVEs
On CISA KEVno
Public exploityes
Published2001-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
francisco burziphp-nuke

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD