PHPNUKE 6 XSS Vulnerabilities

From: Mark Grimes (mark@stateful.net)
Date: 09/24/02


Date: Tue, 24 Sep 2002 11:37:06 -0700
From: Mark Grimes <mark@stateful.net>
To: bugtraq@securityfocus.com

http://www.phpnuke.org/modules.php?name=Search

Enter: ><script>alert(document.cookie);</script>
in form, click Search.

Needless to say these bugs won't go away.

The vendor WOULD HAVE been contacted if they just gave an email address
without having to subscribe to nukesupport/phpnuke - maybe I don't use it.

Likewise the author of PHP-NUKE has a submission form for bug reporting
(buried in a FAQ for unsubscribed people -- why do I need to dig for a
contact address?), but that also has a XSS vulnerability - *SIGH*
Nor HTML nor plain text will do through the submission form without the
javascript being executed or stripped. Instead of implying &gt's and
&lt's in an email, I am posting here.

-- 
Mark Grimes <mark@stateful.net>
Stateful Labs



Relevant Pages

  • [Full-Disclosure] RE: its all about [timing] responsibility
    ... The bug was created by the developing vendor. ... If it is less expensive to fix bugs after the fact, ... commercial vendor money even if it is to just answer the phone or email. ... Most of the responsibility ...
    (Full-Disclosure)
  • Re: OCO, Requirements, etc
    ... I worked for a software vendor and our average in problems were 80% ... configuration/installation and about 20% real bugs in code. ... Subject: OCO, Requirements, etc ... would be now with IBM's reduced support staff. ...
    (bit.listserv.ibm-main)
  • Re: IBM says AMD dead in 5yrs ... -- Microsoft Monopoly vs. IBM monopoly
    ... >>If not then the vendor finds out about it along with everyone else. ... >And we considered that as a security risk. ... Which is why the vendor NEEDS TO PROVIDE A REPORTING MECHANISM ... >sites with enthusiastic kiddies and/or scientists), bugs could ...
    (comp.os.vms)
  • Re: Funny article
    ... It would be very interesting to see any results that try to compare ... the timeliness of vendor response. ... some of those timelines. ... - the unknown percentage of bugs that were discovered and fixed by ...
    (Bugtraq)
  • Re: Complicated Disclosure Scenario
    ... From the SecurityFocus info on Vuln-Dev: ... There are many forums for reporting security bugs and distributing ... > I informed this vendor, who is by no means short on resources, that I ...
    (Vuln-Dev)