PHP-Nuke Private Message HTML Injection Vulnerability
BID:5476
Info
PHP-Nuke Private Message HTML Injection Vulnerability
| Bugtraq ID: | 5476 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 15 2002 12:00AM |
| Updated: | Aug 15 2002 12:00AM |
| Credit: | Discovered by "<-delusion->" <[email protected]>. |
| Vulnerable: |
PostNuke Development Team PostNuke 0.703 PostNuke Development Team PostNuke 0.71 PostNuke Development Team PostNuke 0.70 PostNuke Development Team PostNuke 0.64 PostNuke Development Team PostNuke 0.63 PostNuke Development Team PostNuke 0.62 Francisco Burzi PHP-Nuke 5.6 Francisco Burzi PHP-Nuke 5.5 Francisco Burzi PHP-Nuke 5.4 Francisco Burzi PHP-Nuke 5.3.1 Francisco Burzi PHP-Nuke 5.2 a Francisco Burzi PHP-Nuke 5.2 Francisco Burzi PHP-Nuke 5.1 Francisco Burzi PHP-Nuke 5.0.1 Francisco Burzi PHP-Nuke 5.0 |
| Not Vulnerable: | |
Discussion
PHP-Nuke Private Message HTML Injection Vulnerability
PHP-Nuke is a popular web based Portal system. Implemented in PHP, it is available for a range of systems, including Microsoft Windows and Linux.
PHP-Nuke allows users to send private messages to each other. Reportedly, it is possible to include arbitrary HTML code in these messages, including malicious JavaScript. If another user of the system views a malicious message, the script code will execute within the context of the vulnerable site.
Post-Nuke has also been reported as being vulnerable to this issue.
PHP-Nuke is a popular web based Portal system. Implemented in PHP, it is available for a range of systems, including Microsoft Windows and Linux.
PHP-Nuke allows users to send private messages to each other. Reportedly, it is possible to include arbitrary HTML code in these messages, including malicious JavaScript. If another user of the system views a malicious message, the script code will execute within the context of the vulnerable site.
Post-Nuke has also been reported as being vulnerable to this issue.
Exploit / POC
PHP-Nuke Private Message HTML Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
PHP-Nuke Private Message HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHP-Nuke Private Message HTML Injection Vulnerability
References:
References:
- PHPNuke INP Homepage (PHPNuke INP)
- PostNuke Homepage (PostNuke Development Team)