BugTraq
PHP-Nuke 7.4 Multiple XSS Vulnerabilities Patch Sep 05 2004 11:00AM
Pierquinto Manco (mantra ntj it)


***************************************************************

CODEBUG LABS

PATCH #1 to [XSS] Vulnerabilities in Admin Panel of PHP-NUKE 7.4

***************************************************************

To Patch your admin panel from this vulnerabilities hurricane you have to

apply this code to your admin.php file:

if ( !empty($HTTP_GET_VARS['admin']) ) {

die("Shit! Mantra wins =)");

}

if ( !empty($HTTP_POST_VARS['admin']) ) {

die("Shit! Mantra wins =)");

}

-) Note

Previous patch(CODEBUG #1,#2,#3) isn't enough performant.

Try this one.

There are a lot of this problem in PHP-Nuke 7.4, my patch will check

the content of $_POST[admin] and $_GET[admin].

I'm going to post all this vulnerabilities on my site...

http://www.mantralab.org

**************************************************************

http://www.mantralab.org

**************************************************************

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus