Unrated severityNVD Advisory· Published Aug 31, 2006· Updated Apr 16, 2026
CVE-2006-4480
CVE-2006-4480
Description
Incomplete blacklist vulnerability in the nk_CSS function in nuked.php in Nuked-Klan 1.7 SP4.3 allows remote attackers to bypass anti-XSS features and inject arbitrary web script or HTML via JavaScript in an attribute value that is not in the blacklist, as demonstrated using the STYLE attribute of a B element.
Affected products
1- cpe:2.3:a:nuked-klan:nuked-klan:1.7_sp4.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.