[30711] in bugtraq
cross site scripting htmltonuke
daemon@ATHENA.MIT.EDU (jocanor jocanor)
Sat Jul 12 18:44:16 2003
Date: 12 Jul 2003 17:02:52 -0000
Message-ID: <20030712170252.5019.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: jocanor jocanor <jocanor2002@hotmail.com>
To: bugtraq@securityfocus.com
I find a bug in some versions of htmltonuke.
servers with php-nuke installed are not vulnerables
some versions of htmltonuke only have permisions to acces to html files,
but if you tipe the script before a invalid html file, the script are
executed.
exploit:
http://www.example.com/htmltonuke.php?filnavn=[SCRIPT]%20example.html