10 lines
No EOL
719 B
Text
10 lines
No EOL
719 B
Text
source: https://www.securityfocus.com/bid/10206/info
|
|
|
|
Multiple vulnerabilities were reported to exist in Protector System, which is a third-party module for PHP-Nuke. Cross-site scripting and SQL injection vulnerabilities were reported.
|
|
|
|
Exploitation of these issues may reveal sensitive information, allow for account hijacking, content manipulation and attacks against the underlying database.
|
|
|
|
These issues were reported to exist in Protector System 1.15b1. Other versions may also be affected.
|
|
|
|
http://www.example.com/nuke72/admin/modules/blocker_query.php?target=foobar.com">[xss code here]
|
|
http://www.example.com/nuke72/admin/modules/blocker_query.php?target=foobar.com&queryType=all&portNum=foobar[xss code here] |