Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHPNuke Multiple Module Cross-Site Scripting Vulnerabilities

PHPNuke is reported prone to multiple cross-site scripting vulnerabilities affecting various modules. The affected modules include 'Search', 'FAQ', and 'Encyclopedia'. The 'banners.php' script is also affected.

An attacker can exploit these issues by creating a malicious link containing HTML and script code and send this link to a vulnerable user. This can allow for theft of cookie-based authentication credentials and other attacks.

PHPNuke 7.6 and prior versions are reportedly affected by these issues.







 

Privacy Statement
Copyright 2008, SecurityFocus