PHP-Nuke Reviews Module Cross-Site Scripting Vulnerability
BID:10493
Info
PHP-Nuke Reviews Module Cross-Site Scripting Vulnerability
| Bugtraq ID: | 10493 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 08 2004 12:00AM |
| Updated: | Jun 08 2004 12:00AM |
| Credit: | Discovery is credited to Dark Bicho <[email protected]>. |
| Vulnerable: |
Francisco Burzi PHP-Nuke 7.3 Francisco Burzi PHP-Nuke 7.2 Francisco Burzi PHP-Nuke 7.1 Francisco Burzi PHP-Nuke 7.0 FINAL Francisco Burzi PHP-Nuke 7.0 Francisco Burzi PHP-Nuke 6.9 Francisco Burzi PHP-Nuke 6.7 Francisco Burzi PHP-Nuke 6.6 Francisco Burzi PHP-Nuke 6.5 RC3 Francisco Burzi PHP-Nuke 6.5 RC2 Francisco Burzi PHP-Nuke 6.5 RC1 Francisco Burzi PHP-Nuke 6.5 FINAL Francisco Burzi PHP-Nuke 6.5 BETA 1 Francisco Burzi PHP-Nuke 6.5 Francisco Burzi PHP-Nuke 6.0 |
| Not Vulnerable: | |
Discussion
PHP-Nuke Reviews Module Cross-Site Scripting Vulnerability
PHP-Nuke 'reviews' module is prone to a cross-site scripting vulnerability. These issue could allow an attacker to steal cookie-based authentication credentials. It is reported that the application does not sanitize user-supplied data through the 'id' parameter.
This vulnerability is likely to be fixed in the current versions of PHP-Nuke. This issue may have surfaced earlier, however, this has not been confirmed. This BID will be updated or retired as more information becomes available.
PHP-Nuke 'reviews' module is prone to a cross-site scripting vulnerability. These issue could allow an attacker to steal cookie-based authentication credentials. It is reported that the application does not sanitize user-supplied data through the 'id' parameter.
This vulnerability is likely to be fixed in the current versions of PHP-Nuke. This issue may have surfaced earlier, however, this has not been confirmed. This BID will be updated or retired as more information becomes available.
Exploit / POC
PHP-Nuke Reviews Module Cross-Site Scripting Vulnerability
No exploit is required.
The following proof of concept is available:
http://www.example.com/nuke1/modules.php?name=Reviews&rop=postcomment&id='&title=a
No exploit is required.
The following proof of concept is available:
http://www.example.com/nuke1/modules.php?name=Reviews&rop=postcomment&id='&title=a
Solution / Fix
PHP-Nuke Reviews Module Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHP-Nuke Reviews Module Cross-Site Scripting Vulnerability
References:
References:
- PHPNuke INP Homepage (PHPNuke INP)
- Multiple vulnerabilities PHP-Nuke (Dark Bicho
) - RE: Multiple vulnerabilities PHP-Nuke (Jeruvy
) - RE: Multiple vulnerabilities PHP-Nuke (Jeruvy
) - Re: Multiple vulnerabilities PHP-Nuke (Squid
)