Postnuke XSS fixed

From: Muhammad Faisal Rauf Danka (mfrdat_private)
Date: Tue Oct 01 2002 - 21:10:21 PDT

  • Next message: Matt Moore: "wp-02-0011: Jetty CGIServlet Arbitrary Command Execution"

    on 26th Sep the following url:
    http://news.postnuke.com/modules.php?op=modload&name=News&file=article&sid=>alert(document.cookie);</script>
    
    used to give Alert PopUp and 
    Error:
    DB Error: getArticles: 1064: You have an error in your SQL syntax near '='
    at line 23
    
    now it gives:
    Sorry - $HTTP_GET_VARS contains javascript...
    
    Prompt fix by PostNuke team, great work Keep it up! :)
    
    
    Regards
    --------
    Muhammad Faisal Rauf Danka
    
    Head of GemSEC / Chief Technology Officer
    Gem Internet Services (Pvt) Ltd.
    web: www.gem.net.pk
    Key Id: 0x784B0202
    Key Fingerprint: 6F8C EDCF 6C6E 06A5 48D7 6A20 C592 484B 
    784B 0202
    
    _____________________________________________________________
    ---------------------------
    [ATTITUDEX.COM]
    http://www.attitudex.com/
    ---------------------------
    
    _____________________________________________________________
    Select your own custom email address for FREE! Get youat_private w/No Ads, 6MB, POP & more! http://www.everyone.net/selectmail?campaign=tag
    



    This archive was generated by hypermail 2b30 : Wed Oct 02 2002 - 12:01:34 PDT