AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
November 20, 2008, 07:25:11 PM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 4625 Members
Latest Member: infomorip
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  PostNuke  |  Topic: PostNuke SQL Injection and Cross Site Scripting Vulnerabilities 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: PostNuke SQL Injection and Cross Site Scripting Vulnerabilities  (Read 1026 times)
AlphaWolf
AOT Administrator
Administrator
Hero Member
*****
Offline Offline

Posts: I am a geek!!



View Profile WWW
PostNuke SQL Injection and Cross Site Scripting Vulnerabilities
« on: May 28, 2005, 09:41:46 PM »

 FrSIRT Advisory : FrSIRT/ADV-2005-0643
CVE Reference : GENERIC-MAP-NOMATCH
Rated as : Moderate Risk
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2005-05-28

 * Technical Description *

Two vulnerabilities were identified in PostNuke, which may be exploited by malicious users to execute arbitrary SQL commands or conduct cross site scripting attacks. These flaws are due to an input validation error in the "readpmsg.php" script that does not properly filter the "start" parameter, which may be exploited to conduct SQL injection attacks or cause arbitrary scripting code to be executed by the user's browser.

 * Affected Products *

PostNuke version 0.76 RC4 and prior

 * Solution *

Apply the patch PNSA 2005-2 :
http://news.postnuke.com/Downloads-index-req-getit-lid-471.html

 * References *

http://www.frsirt.com/english/advisories/2005/0643
http://www.securityreason.com/adv/PostNuke_CriticalSQL.asc
Logged

AlphaOne Tech Webmaster Resources
http://www.alphaone-tech.com/resources/
Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  PostNuke  |  Topic: PostNuke SQL Injection and Cross Site Scripting Vulnerabilities « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!