Back
CVE-2003-1238
Cross-site scripting vulnerability (XSS) in Nuked-Klan 1.3 beta and earlier allows remote attackers to steal authentication information via cookies by injecting arbitrary HTML or script into op of the (1) Team, (2) News, and (3) Liens modules.
Published: Dec 31, 2003
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (4)
| Vendor | Product | Version |
|---|---|---|
| nuked-klan | nuked-klan | 1.2 |
| nuked-klan | nuked-klan | 1.2_beta |
| nuked-klan | nuked-klan | 1.3 |
| nuked-klan | nuked-klan | 1.3_beta |
GitHub Security Advisory GHSA-mxgp-xv2m-5j79
Cross-site scripting vulnerability (XSS) in Nuked-Klan 1.3 beta and earlier allows remote...
References (8)
- http://archives.neohapsis.com/archives/bugtraq/2003-02/0276.html Exploit
- http://archives.neohapsis.com/archives/bugtraq/2003-03/0275.html Exploit
- http://www.iss.net/security_center/static/11420.php
- http://www.securityfocus.com/bid/6916 Exploit
- http://archives.neohapsis.com/archives/bugtraq/2003-02/0276.html Exploit
- http://archives.neohapsis.com/archives/bugtraq/2003-03/0275.html Exploit
- http://www.iss.net/security_center/static/11420.php
- http://www.securityfocus.com/bid/6916 Exploit
Risk Scores
CVSS Score
5.8 / 10
EPSS Score
2.09%
Top 20% most likely to be exploited
Threat Score
23.8 / 100
Data Sources
NVD
EPSS
GitHub