Cross-site scripting (XSS) vulnerability in block-Forums.php in the Splatt Forum module for PHP-Nuke 6.x allows remote attackers to inject arbitrary web script or HTML via the subject parameter.Referenceshttp://www.securityfocus.com/archive/1/317230/30/25220/threadedhttp://secunia.com/advisories/8478https://exchange.xforce.ibmcloud.com/vulnerabilities/11675http://www.securityfocus.com/archive/1/316925/30/25250/threadedhttp://securityreason.com/securityalert/3718http://www.securityfocus.com/bid/7248