Hosting generously provided by
|
|
5 PHPNuke Cross Site Scripting holes
|
From: frog frog <leseulfrog@hotmail.com>
To: bugtraq@securityfocus.com
Subject: PHPNuke holes
Status: O
Here a few holes that i've found in PHPNuke.
5 Cross Site Scripting.
http://phpnuke.org/modules.php?name=Downloads&d_op=viewdownloaddetails&lid=02&ttitle=[JAVASCRIPT]
http://phpnuke.org/modules.php?name=Downloads&d_op=ratedownload&lid=118&ttitle=[JAVASCRIPT]
http://phpnuke.org/modules.php?op=modload&name=Members_List&file=index&letter=[JAVASCRIPT]
http://phpnuke.org/submit.php?subject=[JAVASCRIPT]&story=[JAVASCRIPT]&storyext=[JAVASCRIPT]&op=Preview
http://phpnuke.org/user.php?op=userinfo&uname=[JAVASCRIPT] ==> This hole was not found by
Aurelien Cabezon.
and /admin.php?upload=Go! who's the same that upload=1 .
frog-man
|
|
|
Information contained on this website may not be copied without explicit permission.
Best Viewed with Netscape.
|
|
|
Subscribe to CGISecurity.com
|
|

|
|
|
|
The Web Security Mailing List
|
|
|
|
|
Contact us
|
Post News, get linkage!
|
|
|

|