Multiple PHP-Nuke HTML Injection Vulnerabilities
BID:7432
Info
Multiple PHP-Nuke HTML Injection Vulnerabilities
| Bugtraq ID: | 7432 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2003 12:00AM |
| Updated: | Apr 24 2003 12:00AM |
| Credit: | Discovery of these issues is credited to "Frog Man" <[email protected]>. |
| Vulnerable: |
Francisco Burzi PHP-Nuke 6.5 FINAL |
| Not Vulnerable: | |
Discussion
Multiple PHP-Nuke HTML Injection Vulnerabilities
Multiple HTML injection vulnerabilities have been reported in PHP-Nuke. PHP-Nuke does not sufficiently sanitize HTML and script code from various input fields. This input may be displayed throughout various places in the forum and other modules.
These issues were reported in PHP-Nuke 6.5 Final. Other versions may also be affected.
Multiple HTML injection vulnerabilities have been reported in PHP-Nuke. PHP-Nuke does not sufficiently sanitize HTML and script code from various input fields. This input may be displayed throughout various places in the forum and other modules.
These issues were reported in PHP-Nuke 6.5 Final. Other versions may also be affected.
Exploit / POC
Multiple PHP-Nuke HTML Injection Vulnerabilities
There is no exploit required.
There is no exploit required.
Solution / Fix
Multiple PHP-Nuke HTML Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Multiple PHP-Nuke HTML Injection Vulnerabilities
References:
References:
- PHPNuke INP Homepage (PHPNuke INP)
- PHP-Nuke 6.5 FINAL Cross Site Scripting ("Frog Man"
)