PHP-Nuke Block-Forums.PHP Subject HTML Injection Vulnerability
BID:7248
Info
PHP-Nuke Block-Forums.PHP Subject HTML Injection Vulnerability
| Bugtraq ID: | 7248 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 31 2003 12:00AM |
| Updated: | Mar 31 2003 12:00AM |
| Credit: | Discovery credited to <[email protected]>. |
| Vulnerable: |
Francisco Burzi PHP-Nuke 6.5 RC3 Francisco Burzi PHP-Nuke 6.5 RC2 Francisco Burzi PHP-Nuke 6.5 RC1 Francisco Burzi PHP-Nuke 6.5 BETA 1 Francisco Burzi PHP-Nuke 6.5 |
| Not Vulnerable: | |
Discussion
PHP-Nuke Block-Forums.PHP Subject HTML Injection Vulnerability
The PHP-Nuke 'block-Forums.php' does not sufficiently sanitize data supplied via form fields, making it prone to HTML injection attacks. This could allow for execution of hostile HTML and script code in the web client of a user who visits a web page that contains the malicious code.
The PHP-Nuke 'block-Forums.php' does not sufficiently sanitize data supplied via form fields, making it prone to HTML injection attacks. This could allow for execution of hostile HTML and script code in the web client of a user who visits a web page that contains the malicious code.
Exploit / POC
PHP-Nuke Block-Forums.PHP Subject HTML Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
PHP-Nuke Block-Forums.PHP Subject HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHP-Nuke Block-Forums.PHP Subject HTML Injection Vulnerability
References:
References: