AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
January 07, 2009, 04:25:32 PM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 5333 Members
Latest Member: armstrong
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Php-Nuke Alerts  |  Topic: Php Nuke Alert! 0 Members and 0 Guests are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: Php Nuke Alert!  (Read 816 times)
AlphaWolf
AOT Administrator
Administrator
Hero Member
*****
Offline Offline

Posts: I am a geek!!



View Profile WWW
Php Nuke Alert!
« on: February 18, 2005, 11:55:15 PM »

 K-OTik Security Advisory : KOTIK/ADV-2005-0165
CVE Reference : CAN-2005-0433 - CAN-2005-0434
Rated as : Low
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2005-02-15

 * Technical Description *

Several vulnerabilities were identified in PhpNuke, which could be exploited by attackers to conduct Cross Site Scripting attacks. The first flaw resides in the "db/db.php", "mainfile.php", "modules/Downloads/index.php", and "modules/Web_Links/index.php" files, which may be exploited to determine the installation path. The second vulnerability resides in the "modules/Downloads/index.php" and "modules/Web_Links/index.php" files, when handling specially crafted "newlinkshowdays" and "newdownloadshowdays" parameters, which may be exploited to conduct Cross Site Scripting attacks.

 * Affected Products *

PHP-Nuke version 7.6 and prior

 * Solution *

K-OTik Security is not aware of any official supplied patch for this issue.

 * References *

http://www.k-otik.com/english/advisories/2005/0165
http://www.waraxe.us/advisory-40.html
« Last Edit: February 19, 2005, 12:01:14 AM by AlphaWolf » Logged

AlphaOne Tech Webmaster Resources
http://www.alphaone-tech.com/resources/
Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Php-Nuke Alerts  |  Topic: Php Nuke Alert! « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!