PHPNuke Splatt Forum Module Cross Site Scripting Vulnerability
BID:7483
Info
PHPNuke Splatt Forum Module Cross Site Scripting Vulnerability
| Bugtraq ID: | 7483 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 01 2003 12:00AM |
| Updated: | May 01 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to morning_wood <[email protected]>. |
| Vulnerable: |
Splatt Forum 4.0 |
| Not Vulnerable: | |
Discussion
PHPNuke Splatt Forum Module Cross Site Scripting Vulnerability
Splatt Forum is a public message board plugin designed to be used with PHPNuke.
It has been reported that Splatt Forum does not sufficiently filter user supplied URI parameters for the Splatt Forum 'Search' function.
As a result of this deficiency, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of a legitimate user.
This vulnerability was reported to affect Splatt Forum version 4.0, it is not currently known if other versions are affected.
Splatt Forum is a public message board plugin designed to be used with PHPNuke.
It has been reported that Splatt Forum does not sufficiently filter user supplied URI parameters for the Splatt Forum 'Search' function.
As a result of this deficiency, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of a legitimate user.
This vulnerability was reported to affect Splatt Forum version 4.0, it is not currently known if other versions are affected.
Exploit / POC
PHPNuke Splatt Forum Module Cross Site Scripting Vulnerability
The following proof of concept has been supplied:
Perform a search with the keywords:
<iframe src="http://www.example.com">
The following proof of concept has been supplied:
Perform a search with the keywords:
<iframe src="http://www.example.com">
Solution / Fix
PHPNuke Splatt Forum Module Cross Site Scripting Vulnerability
Solution:
The vendor has released a patch to address this issue. The effectiveness of this patch, however, has not been confirmed.
Splatt Forum 4.0
Solution:
The vendor has released a patch to address this issue. The effectiveness of this patch, however, has not been confirmed.
Splatt Forum 4.0
-
Splatt Splatt Forum 4.0 Fix 1
http://www.splatt.it/modules.php?name=Downloads&d_op=viewdownloaddetai ls&lid=166&ttitle=Splatt%20Forum%204.0%20Fix%201
References
PHPNuke Splatt Forum Module Cross Site Scripting Vulnerability
References:
References:
- Splatt Homepage (Splatt)
- Multiple Vulnerabilities in Splatt Forum 4.0 (Frame4 Security Systems
)