about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PostNuke Phoenix Module Parameter Remote Cross-Site Scripting Vulnerability


Title PostNuke Phoenix Module Parameter Remote Cross-Site Scripting Vulnerability
Published 2005-04-08-12:00AM
Updated 2005-05-21-09:43PM
Class Input Validation Error
CVE   CAN-2005-1048
Remote  Yes
Local  No
Credit  dcrab <dcrab@hackerscenter.com> is credited with the discovery of this issue.
Vulnerable  PostNuke Development Team PostNuke Phoenix 0.760 RC3
Not Vulnerable  PostNuke Development Team PostNuke Phoenix 0.750 b
Code   The following proof of concept is available:

http://www.example.com/admin.php?module=">&lt;script&gt;alert(document.cookie)&lt;/script&gt;&op=main&POSTNUKESID=355776cfb622466924a7096d4471a480
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 04:51:18 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
&amp;a Free Downl svftp www.dasuan Gay model Allsex.com meta t308t news for C sexanimal Solaris 8. Sexis www.heibai www.wooxee /search/ex Lokalxxx c Vidio porn myspace.cn Quake 3 Simpleboar ayfreeman1 news for c www.it197. Sql injext www.11718. sexrhot www.woaibi ip board 2 news for c news for C mygam Www.trisha http://bla NUDEGril Sexmovies Crack D/r/ jshuwei.or Vidoe full namitha se News Searc news for C bie bie ms Savita taixiangqu www.roo7al www.hot.gi 200 /compo Www.Girlse maxcpm.inf news.ltdts