phpMyAdmin theme and db Cross-Site Scripting Vulnerabilities More about

Posted on Monday, May 15, 2006 @ 09:04:05 CDT in Security
by Raven

TITLE: phpMyAdmin "theme" and "db" Cross-Site Scripting Vulnerabilities

SECUNIA ADVISORY ID: SA20113

VERIFY ADVISORY: http://secunia.com/advisories/20113/

CRITICAL: Less critical

IMPACT: Cross Site Scripting

WHERE: >From remote

SOFTWARE: phpMyAdmin 2.x http://secunia.com/product/1720/

DESCRIPTION:
Two vulnerabilities have been reported in phpMyAdmin, which can be exploited by malicious people to conduct cross-site scripting attacks.

1) Input passed to the "theme" parameter isn't properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

The vulnerability has been reported in versions prior to 2.8.0.4 for the 2.8.0 branch.

2) Input passed to the "db" parameter isn't properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

The vulnerability has been reported in some versions prior to 2.8.0.4.

SOLUTION: Update to version 2.8.0.4.
http://www.phpmyadmin.net/home_page/downloads.php

PROVIDED AND/OR DISCOVERED BY:
1) Reported by the vendor.
2) The vendor credits Sven Vetsch/Disenchant.

ORIGINAL ADVISORY:
http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2006-2
 

 

phpBB foing Module phpbb_root_path File Inclusion More about

Posted on Monday, May 15, 2006 @ 08:57:44 CDT in Security
by Raven

TITLE: phpBB foing Module "phpbb_root_path" File Inclusion

SECUNIA ADVISORY ID: SA20092

VERIFY ADVISORY: http://secunia.com/advisories/20092/

CRITICAL: Highly critical

IMPACT: System access

WHERE: >From remote

SOFTWARE: foing 0.x (phpBB module)
http://secunia.com/product/9935/

DESCRIPTION:
Kurdish Security has discovered some vulnerabilities in the foing module for phpBB, which can be exploited by malicious people to compromise a vulnerable system.

Input passed to the "phpbb_root_path" parameter in index.php,song.php, faq.php, list.php, gen_m3u.php, and playlist.php isn't properly verified, before it is used to include files. This can be exploited to include arbitrary files from external and local resources.

The vulnerabilities have been confirmed in version 0.7.0 and have also been reported in versions 0.6.0, 0.5.0, 0.4.0, 0.3.0, and 0.2.0. Other versions may also be affected.

SOLUTION: Edit the source code to ensure that input is properly verified.

Use another product.

PROVIDED AND/OR DISCOVERED BY: Kurdish Security

ORIGINAL ADVISORY:
http://kurdishsecurity.blogspot.com/2006/05/kurdish-security-7-foing-remote-file.html
 

 

Content Plus 1.0.0 Released, Get Your Copy Now! More about Read More...

Posted on Monday, May 15, 2006 @ 01:18:18 CDT in Add-Ons
by Raven

slaytanic_wehrmacht writes:  
Content Plus is a mega enhanced version of PHP-Nuke's default Content Module, have a lot of new features and also more eye-candy.

Features:

- Users can add new pages.
- Ability to export content as PDF
- Users can share page with friends.
- Users can get a printer friendly page.
- Improved the eye-candy.

Get your copy Right Now!
 Read More...
 

 

My opinion of the Nuke Community More about Read More...

Posted on Monday, May 15, 2006 @ 01:16:40 CDT in Opinion
by Raven

pcnuke writes:  
My opinion of the Nuke Community(www.pcnuke.com):

Date: 05.14.06

One thing the team at PCN Systems has found out working with the PHP-Nuke portal system (in our short time within the community) is that it will never be up to date & can have many security issues. While members & staff of this website enjoy using phpnuke and variations of the program. Part of the fun of it is messing with it, and converting sections of it they way you want it to be. They main thing you must remember is that its a free program and is Open Source, so you can distribute it, and change it, and any addons created for it, anyway you would like. Many people will use it as BASIS to develop a new FORK from, converting areas of the code they way they choose. We want everyone here at www.pcnuke.com to know that versions found on our website are not FORKS, they are truly php-nuke based at heart, and any addon created for phpnuke will always work with all systems found on this website.

The main reason for the programs flaws are caused from its developer and bad coding he releases to the public. While the overall idea of the system is great and I mean no dis-respect to the developer of PHP-Nuke (FB) www.phpnuke.org , the program could be made better by its dev... by rechecking its operations in a couple of browsers, prior to releasing it to the public. Remember Php-Nuke is also a fork created from a previous open source poratl system.
 Read More...
 

 

New Themes from DesignWicked and Phpcusa More about

Posted on Monday, May 15, 2006 @ 01:09:51 CDT in PHP-Nuke Themes
by Raven

refiner writes:  
Themes PH-APOTHUS BLUE AND PH-APOTHUS RED have benn released today, both theme are tech looking and come with matchin forum, flash nav in the header (links can be changed thru the text file nav.txt) second flash menu in the footer, scrolling download and weblink, forum header with flash nav. You can see both theme and all other Phpcusa & DesignWicked theme at newly opened phpcusa themes site Phpcusa & DesignWicked Themes. PHAPOTHUS BLUE is named PH-APOTHUSB. PHAPOTHUS RED is named PH-APOTHUSR.
 

 
nukeevangelist writes:  
good news from jmagar.com - celebrate the long development of the MyHeadlinesmodule [change-log ]

travel to the developersite jmagar.com and read good news about Myheadlines v 4.3.2 Release Candidate 1

Mike Agar: "I'm now testing the latest version of MyHeadlines. There are so many changes and improvements that I want to work out the kinks before going public with it. Also the jokers at SourceForge are having difficulty with the CVS servers so I can't commit my changes, and thus am unable to make a proper release. Not to worry, in about 2 weeks we'll make this public, and I'll even include my latest source tree in OPML Format!"

at the developersite you can see the long change-log
 



Page 318 of 659 (3950 total stories) [ << | < | 313 | 314 | 315 | 316 | 317 | 318 | 319 | 320 | 321 | 322 | 323 | > | >> ]  

News ©

Site Info

Last SeenLast Seen
  • kguske
  • rain
Server TrafficServer Traffic
  • Total: 573,273,364
  • Today: 138,817
Server InfoServer Info
  • Aug 01, 2026
  • 02:09 pm CDT