If you have found a vulnerability, please send to our SecurityAlert Database : secalert()securityreason()com
Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive : exploit()securityreason()com
Details : SecurityReason Advisory
Topic : PostNuke XSS 0.760{RC2,RC3} SecurityAlert : 17 SecurityRisk : Medium (About) Remote Exploit : Yes Local Exploit : Yes Exploit Given : Yes Credit : Maksymilian Arciemowicz Date : 08.09.2005
Affected Software :
PostNuke 0.760{RC2,RC3}
Advisory Text :
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
[PostNuke XSS 0.760{RC2,RC3} cXIb8O3.6]
Author: Maksymilian Arciemowicz ( cXIb8O3 )
Date: 4.3.2005
from SECURITYREASON.COM
- --- 0.Description ---
PostNuke: The Phoenix Release (0.750)
PostNuke is an open source, open developement content management system
(CMS). PostNuke started as a fork from PHPNuke (http://www.phpnuke.org) and
provides many enhancements and improvements over the PHP-Nuke system.
PostNuke
is still undergoing development but a large number of core functions are
now
stabilising and a complete API for third-party developers is now in place.
If you would like to help develop this software, please visit our homepage
at http://noc.postnuke.com/
You can also visit us on our IRC Server irc.postnuke.com channel
#postnuke-support
#postnuke-chat
#postnuke
Or at the Community Forums located at:
http://forums.postnuke.com/
- --- 1. Cross Site Scripting in RSS module ---
1.0
http://[HOST]/[DIR]/modules/RSS/pnincludes/scripts/magpie_slashbox.php?rss_
url=[XSS]
Warning: main(/home/kellan/projs/magpierss/scripts/Smarty/Smarty.class.php)
[function.main]: failed to open stream: No such file or directory in
/www/PostNuke-0.760-RC3/html/modules/RSS/pnincludes/scripts/simple_smarty.p
hp on line 8
Fatal error: main() [function.require]: Failed opening required
'/home/kellan/projs/magpierss/scripts/Smarty/Smarty.class.php'
(include_path='.:') in
/www/PostNuke-0.760-RC3/html/modules/RSS/pnincludes/scripts/simple_smarty.p
hp on line 8
Microsoft Device IO Control wrapped by the iphlpapi.dll API shipping with Windows Vista 32 bit and 64 bit contains a possibly exploitable, buffer overflow corrupting kernel memory.