PHP-Nuke CookieDecode远程跨站脚本漏洞

PHP-Nuke CookieDecode远程跨站脚本漏洞

漏洞ID 1107874 漏洞类型 输入验证
发布时间 2004-04-13 更新时间 2005-10-20
图片[1]-PHP-Nuke CookieDecode远程跨站脚本漏洞-安全小百科CVE编号 CVE-2004-1930
图片[2]-PHP-Nuke CookieDecode远程跨站脚本漏洞-安全小百科CNNVD-ID CNNVD-200404-016
漏洞平台 PHP CVSS评分 4.3
|漏洞来源
https://www.exploit-db.com/exploits/23990
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200404-016
|漏洞详情
PHP-Nuke是一个广为流行的网站创建和管理工具,它可以使用很多数据库软件作为后端,比如MySQL、PostgreSQL、mSQL、Interbase、Sybase等。PHP-Nuke包含的mainfile.php脚本cookiedecode()函数对用户提交输入缺少充分过滤,远程攻击者可以利用这个漏洞进行跨站脚本攻击,可获得用户敏感信息。’cookiedecode()’函数不正确过滤用户提供的cookie参数,攻击者构建恶意连接,诱使用户访问,可导致恶意代码在用户浏览器上执行,使攻击者获得目标用户敏感信息。
|漏洞EXP
source: http://www.securityfocus.com/bid/10128/info

Reportedly PHP-NuKe is prone to a remote cross-site scripting vulnerability. This issue is due to a failure of the 'cookiedecode()' function to properly sanitize user supplied cookie parameters.

These issues could permit a remote attacker to create a malicious link to the vulnerable application that includes hostile HTML and script code. If this link were followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

http://localhost/nuke71/index.php?user=MTo8c2NyaXB0PmFsZXJ0KGRvY3VtZW50LmNvb2tpZSk7PC9zY3JpcHQ%2bZm9vYmFy
|参考资料

来源:XF
名称:phpnuke-cookiedecode-xss(15842)
链接:http://xforce.iss.net/xforce/xfdb/15842
来源:www.waraxe.us
链接:http://www.waraxe.us/index.php?modname=sa&id;=16
来源:BID
名称:10128
链接:http://www.securityfocus.com/bid/10128
来源:SECUNIA
名称:11347
链接:http://secunia.com/advisories/11347
来源:BUGTRAQ
名称:20040412[waraxe-2004-SA#016-Cross-SiteScriptingakaXSSinphpnuke6.x-7.2part3]
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=108182759214035&w;=2

相关推荐: My Postcards MagicCard.CGI Arbitrary File Disclosure Vulnerability

My Postcards MagicCard.CGI Arbitrary File Disclosure Vulnerability 漏洞ID 1101927 漏洞类型 Input Validation Error 发布时间 2002-06-15 更新时间 2…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享