PostNuke Downloads / Web_Links Modules TTitle Cross-site Scripting Vulnerability
BID:8374
Info
PostNuke Downloads / Web_Links Modules TTitle Cross-site Scripting Vulnerability
| Bugtraq ID: | 8374 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2003 12:00AM |
| Updated: | Aug 08 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Lorenzo Hernandez Garcia-Hierro <[email protected]>. |
| Vulnerable: |
PostNuke Development Team PostNuke Phoenix 0.726 PostNuke Development Team PostNuke Phoenix 0.723 PostNuke Development Team PostNuke Phoenix 0.722 PostNuke Development Team PostNuke Phoenix 0.721 PostNuke Development Team PostNuke 0.721 PostNuke Development Team PostNuke 0.703 PostNuke Development Team PostNuke 0.72 PostNuke Development Team PostNuke 0.71 PostNuke Development Team PostNuke 0.70 PostNuke Development Team PostNuke 0.64 PostNuke Development Team PostNuke 0.63 PostNuke Development Team PostNuke 0.62 PostNuke Development Team PostNuke 0.7 |
| Not Vulnerable: | |
Discussion
PostNuke Downloads / Web_Links Modules TTitle Cross-site Scripting Vulnerability
It has been reported that a cross site scripting vulnerability exists in the Downlaods and Web_Links modules of PostNuke. It is possible that an attacker may construct a link containing malicious script code that could be executed in a browser of a user who visits the link.
Exploitation could allow theft of authentication cookies.
It has been reported that a cross site scripting vulnerability exists in the Downlaods and Web_Links modules of PostNuke. It is possible that an attacker may construct a link containing malicious script code that could be executed in a browser of a user who visits the link.
Exploitation could allow theft of authentication cookies.
Exploit / POC
PostNuke Downloads / Web_Links Modules TTitle Cross-site Scripting Vulnerability
The following proof of concept has been provided:
http://www.example.com/[PATH]/modules.php?
op=modload&name=Downloads&file=index&req=viewdownloaddetails&lid=[ID]
&ttitle=[Yeye XSS ;-)]"%3e[XSS ATTACK]
http://www.example.com/[PATH]/modules.php?
op=modload&name=Web_Links&file=index&req=viewlinkdetails&lid=[ID]
&ttitle=[MORE ? ;-(]"%3e[XSS ATTACK]
The following proof of concept has been provided:
http://www.example.com/[PATH]/modules.php?
op=modload&name=Downloads&file=index&req=viewdownloaddetails&lid=[ID]
&ttitle=[Yeye XSS ;-)]"%3e[XSS ATTACK]
http://www.example.com/[PATH]/modules.php?
op=modload&name=Web_Links&file=index&req=viewlinkdetails&lid=[ID]
&ttitle=[MORE ? ;-(]"%3e[XSS ATTACK]
Solution / Fix
PostNuke Downloads / Web_Links Modules TTitle Cross-site Scripting Vulnerability
Solution:
Vendor supplied patch and upgrade available:
PostNuke Development Team PostNuke Phoenix 0.721
PostNuke Development Team PostNuke Phoenix 0.722
PostNuke Development Team PostNuke Phoenix 0.723
PostNuke Development Team PostNuke Phoenix 0.726
Solution:
Vendor supplied patch and upgrade available:
PostNuke Development Team PostNuke Phoenix 0.721
-
PostNuke Development Team PostNuke Phoenix 0.726-1
http://download.postnuke.com/pafiledb.php?action=file&id=33
PostNuke Development Team PostNuke Phoenix 0.722
-
PostNuke Development Team PostNuke Phoenix 0.726-1
http://download.postnuke.com/pafiledb.php?action=file&id=33
PostNuke Development Team PostNuke Phoenix 0.723
-
PostNuke Development Team PostNuke Phoenix 0.726-1
http://download.postnuke.com/pafiledb.php?action=file&id=33
PostNuke Development Team PostNuke Phoenix 0.726
-
PostNuke Development Team Members_List patch for pn0.726
http://download.postnuke.com/pafiledb.php?action=file&id=42 -
PostNuke Development Team PostNuke Phoenix 0.726-1
http://download.postnuke.com/pafiledb.php?action=file&id=33
References
PostNuke Downloads / Web_Links Modules TTitle Cross-site Scripting Vulnerability
References:
References:
- [Postnuke-security] PostNuke Security Advisory PNSA 2004-1a (PostNuke Development Team)
- PostNuke Homepage (PostNuke Development Team)
- PostNuke Downloads & Web_Links ttitle variable XSS ( "Lorenzo Hernandez Garcia-Hierro"
) - PostNuke Issues (0.726 && Possibly Older) (JeiAr
)