PostNuke Cross Site Scripting Vulnerability
BID:4350
Info
PostNuke Cross Site Scripting Vulnerability
| Bugtraq ID: | 4350 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 22 2002 12:00AM |
| Updated: | Mar 22 2002 12:00AM |
| Credit: | Discovered by Scott <[email protected]>. |
| Vulnerable: |
PostNuke Development Team PostNuke 0.703 PostNuke Development Team PostNuke 0.71 PostNuke Development Team PostNuke 0.70 PostNuke Development Team PostNuke 0.64 PostNuke Development Team PostNuke 0.63 PostNuke Development Team PostNuke 0.62 PostNuke Development Team PostNuke 0.7 |
| Not Vulnerable: | |
Discussion
PostNuke Cross Site Scripting Vulnerability
PostNuke is a content management system originally forked from the PHP-Nuke project. It is implemented in PHP, and available for Windows, Linux and other Unix based systems.
Cross site scripting vulnerabilites have been reported in some versions of PostNuke. User supplied input may be inserted into the HTML produced by both the index.php and modules.php scripts.
PostNuke is a content management system originally forked from the PHP-Nuke project. It is implemented in PHP, and available for Windows, Linux and other Unix based systems.
Cross site scripting vulnerabilites have been reported in some versions of PostNuke. User supplied input may be inserted into the HTML produced by both the index.php and modules.php scripts.
Exploit / POC
PostNuke Cross Site Scripting Vulnerability
No exploit code required.
No exploit code required.
Solution / Fix
PostNuke Cross Site Scripting Vulnerability
Solution:
This issue has been reported as fixed in the CVS version of PostNuke as of 22 March, 2002.
Solution:
This issue has been reported as fixed in the CVS version of PostNuke as of 22 March, 2002.
References
PostNuke Cross Site Scripting Vulnerability
References:
References:
- [ 524777 ] CSS bugs (scott (rootkidd))
- PostNuke Product Page (PostNuke)