PHPNuke Search Form Cross-Site Scripting Vulnerability
BID:5788
Info
PHPNuke Search Form Cross-Site Scripting Vulnerability
| Bugtraq ID: | 5788 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 24 2002 12:00AM |
| Updated: | Sep 24 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to Mark Grimes <[email protected]>. |
| Vulnerable: |
Francisco Burzi PHP-Nuke 6.5 BETA 1 Francisco Burzi PHP-Nuke 6.0 |
| Not Vulnerable: | |
Discussion
PHPNuke Search Form Cross-Site Scripting Vulnerability
PHPNuke 6.0 is prone to cross-site scripting attacks.
HTML tags are not filtered from links to the 'modules.php' script.
Reportedly, the problem lies in the 'Search' page of the 'modules.php' script. It is possible for a malicious attacker to submit a search string that contains HTML code. The value of this search string is not sanitized before it is included in PHP generated HTML and output to the client.
This attack may be used to steal a user's cookie-based authentication credentials for the vulnerable PHPNuke site.
PHPNuke 6.0 is prone to cross-site scripting attacks.
HTML tags are not filtered from links to the 'modules.php' script.
Reportedly, the problem lies in the 'Search' page of the 'modules.php' script. It is possible for a malicious attacker to submit a search string that contains HTML code. The value of this search string is not sanitized before it is included in PHP generated HTML and output to the client.
This attack may be used to steal a user's cookie-based authentication credentials for the vulnerable PHPNuke site.
Exploit / POC
PHPNuke Search Form Cross-Site Scripting Vulnerability
The following proof of concept was provided:
<script>alert(document.cookie);</script>
It is possible to enter the above in the text field provided by the 'Search' page.
The following proof of concept was provided:
<script>alert(document.cookie);</script>
It is possible to enter the above in the text field provided by the 'Search' page.
Solution / Fix
PHPNuke Search Form Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHPNuke Search Form Cross-Site Scripting Vulnerability
References:
References:
- PHPNuke INP Homepage (PHPNuke INP)
- Multiple phpNuke Modules Vulnerable to Cross-Site Scripting ("Matthew Murphy"
)