PHP-Nuke Reviews Module "title" Parameter Cross-Site Scripting Vulnerability
BID:10755
Info
PHP-Nuke Reviews Module "title" Parameter Cross-Site Scripting Vulnerability
| Bugtraq ID: | 10755 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2004 12:00AM |
| Updated: | Jul 19 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to "DarkBicho" <[email protected]>. |
| Vulnerable: |
Francisco Burzi PHP-Nuke 7.3 Francisco Burzi PHP-Nuke 7.2 Francisco Burzi PHP-Nuke 7.1 Francisco Burzi PHP-Nuke 7.0 FINAL Francisco Burzi PHP-Nuke 7.0 Francisco Burzi PHP-Nuke 0.726 -3 Francisco Burzi PHP-Nuke 0.75 -RC3 |
| Not Vulnerable: | |
Discussion
PHP-Nuke Reviews Module "title" Parameter Cross-Site Scripting Vulnerability
PHP-Nuke 'reviews' module is prone to a cross-site scripting vulnerability. This issue could allow an attacker to steal cookie-based authentication credentials.
An attacker can exploit this issue by creating a malicious link containing HTML and script code. The attacker sends this link to a vulnerable user. When the user follows the link, HTML and script renders in the user's browser.
PHP-Nuke 'reviews' module is prone to a cross-site scripting vulnerability. This issue could allow an attacker to steal cookie-based authentication credentials.
An attacker can exploit this issue by creating a malicious link containing HTML and script code. The attacker sends this link to a vulnerable user. When the user follows the link, HTML and script renders in the user's browser.
Exploit / POC
PHP-Nuke Reviews Module "title" Parameter Cross-Site Scripting Vulnerability
The following example is available:
http://www.example.com/html/modules.php?op=modload&name=Reviews&file=index&req=showcontent&id=1&title=%253cscript>alert%2528document.cookie);%253c/script>
The following example is available:
http://www.example.com/html/modules.php?op=modload&name=Reviews&file=index&req=showcontent&id=1&title=%253cscript>alert%2528document.cookie);%253c/script>
Solution / Fix
PHP-Nuke Reviews Module "title" Parameter Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHP-Nuke Reviews Module "title" Parameter Cross-Site Scripting Vulnerability
References:
References:
- PHPNuke INP Homepage (PHPNuke INP)