PHPNuke多个跨站脚本漏洞

PHPNuke多个跨站脚本漏洞

漏洞ID 1106529 漏洞类型 跨站脚本
发布时间 2001-12-03 更新时间 2005-10-20
图片[1]-PHPNuke多个跨站脚本漏洞-安全小百科CVE编号 CVE-2001-1524
图片[2]-PHPNuke多个跨站脚本漏洞-安全小百科CNNVD-ID CNNVD-200112-201
漏洞平台 PHP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/21166
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200112-201
|漏洞详情
PHP-Nuke5.3.1版本及之前版本存在跨站脚本(XSS)漏洞。远程攻击者可以借助(1)user.php的uname参数,(2)modules.php的ttitle、letter和file参数,(3)submit.php的subject、story和storyext参数,(4)admin.php的upload参数以及(5)friend.php的fname参数注入任意web脚本或HTML。
|漏洞EXP
source: http://www.securityfocus.com/bid/3609/info
 
PHPNuke is a website creation/maintenance tool.
 
PHPNuke is prone to cross-site scripting attacks. It is possible to create a link to the PHPNuke user information page, 'user.php', which contains malicious script code. When the link is clicked by an unsuspecting web user, the malicious script code will be executed on the user in the context of the site running PHPNuke.
 
This attack may be used to steal a user's cookie-based authentication credentials for the vulnerable PHPNuke site.
 
PostNuke is also affected by a number of these issues.
 
This problem has also been reported with other scripts included in the PHPNuke package. More specifically, modules.php, upload.php, friend.php and submit.php are also vulnerable under some circumstances. Different parameters to the user.php script may also be sufficient for a cross-site scripting attack.
 
An additional cross-site scripting vulnerability has been reported in modules.php for PostNuke.
 
**It has been reported that the cross-site scripting issue affecting the 'ttitle' parameter of 'modules.php' script has been re-introduced in newer versions of the PHPNuke application. This issue is reported to affect versions 7.2 and prior. 

http://phpnukesite/modules.php?op=modload&name=Downloads&file=index&req=viewdownloaddetails&lid=2&ttitle=%3Cscript%3Ealert(document.location)%3C/script%3E
|参考资料

来源:prdownloads.sourceforge.net
链接:http://prdownloads.sourceforge.net/phpnuke/PHP-Nuke-5.5.tar.gz
来源:XF
名称:phpnuke-postnuke-css(7654)
链接:http://www.iss.net/security_center/static/7654.php
来源:BID
名称:3609
链接:http://www.securityfocus.com/bid/3609

相关推荐: Calendar Express Search.PHP Cross-Site Scripting Vulnerability

Calendar Express Search.PHP Cross-Site Scripting Vulnerability 漏洞ID 1096210 漏洞类型 Input Validation Error 发布时间 2005-08-08 更新时间 2005-…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享