|
Cross Site Scripting holes in Xoops, PHP-Nuke, NPDS, daCode, Drupal and phpWebSite
|
|
Secunia Advisory:
|
SA7153
|
|
|
Release Date:
|
2002-09-24
|
|
Last Update:
|
2002-10-01
|
|
Popularity:
|
8,765 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Cross Site Scripting
|
|
Where:
|
From remote
|
|
Solution Status:
|
Partial Fix
|
|
| Software: | daCode 1.x Drupal 3.x Drupal 4.x NPDS 4.x SuperCache PHP-Nuke 6.x phpWebSite 0.x Xoops 2.x
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: Multiple content management systems has been found to be vulnerable to injection of HTML code.
The content management systems may have reasons to allow trusted users to insert HTML code, however the systems fail to strip more dangerous parts of the HTML code like if
IMG SRC="javascript:alert('insecure')"
Also it appears to be possible to inject SQL into certain PHP-Nuke scripts:
http://www.nukesite.com/modules.php?name=News&file=article&sid=1234%20or%201=1
This would cause a DoS. It is likely to believe that the SQL injection could be abused to more than a mere DoS.
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|