PHPNuke Cross Scripting...

From: frog frog (leseulfrogat_private)
Date: Fri Dec 14 2001 - 13:30:46 PST

  • Next message: Dimitry Andric: "Re: Win XP IP address hijack?"

    
     ('binary' encoding is not supported, stored as-is)
    Here a few holes that i've found in PHPNuke.
    5 "Cross Site Scripting".
    
    http://phpnuke.org/modules.php?
    name=Downloads&d_op=viewdownloaddetails&lid=0
    2&ttitle=[JAVASCRIPT]
    
    http://phpnuke.org/modules.php?
    name=Downloads&d_op=ratedownload&lid=118&ttitle
    =[JAVASCRIPT]
    
    http://phpnuke.org/modules.php?
    op=modload&name=Members_List&file=index&letter
    =[JAVASCRIPT]
    
    http://phpnuke.org/submit.php?subject=
    [JAVASCRIPT]&story=[JAVASCRIPT]&storyext=
    [JAVASCRIPT]&op=Preview
    
    http://phpnuke.org/user.php?op=userinfo&uname=
    [JAVASCRIPT]
    
    
    and /admin.php?upload=Go! who's the same that 
    upload=1 .
    
    frog-m@n
    



    This archive was generated by hypermail 2b30 : Fri Dec 14 2001 - 15:19:01 PST