mailing list archives
Multiple Vulnerabilities in Splatt Forum 4.0
From: Frame4 Security Systems <webmaster () frame4 com>
Date: 1 May 2003 18:58:36 -0000
FRAME4 SECURITY ADVISORY [FSA-2003:001]
PRODUCT : Splatt Forum 4.0 for PHP-Nuke 6.0
PRODUCT/VENDOR URL : http://www.splatt.it/
TYPE : Vulnerability / Exploit
IMPACT : Medium
SUMMARY : Multiple Vulnerabilities in Splatt Forum 4.0
DISCOVERY DATE : 26/03/2003
PUBLIC RELEASE : 01/05/2003
AFFECTED VERSION(S): Splatt Forum 4.0 (as of discovery date)
FIXED VERSION(S) : Splatt Forum 4.0 Fix 1 (not tested)
VENDOR NOTIFIED : No
Splatt Forum is a MySQL driven, PHP-based forum system that fully
to PHP-Nuke, the popular CMS system by Fransisco Burzi.
We have discovered two vulnerabilities in the vanilla version of Splatt
4.0 for PHP-Nuke 6.0; an XSS Vulnerability and an HTML/Code Injection Flaw.
The vulnerabilities and accompanying exploits were discovered and executed
only one web site, and verified by Webmaster (webmaster () frame4 com).
None. We didn't contact the vendor as 'Splatt' has a very bad track record
it comes to replying to security reports and fixing issues. The web site
vendor is almost entirely in Italian which makes vendor contact difficult.
Please refer to the 'Technical Description' section below, for full
of the problem(s).
"Out-of-the-box" version of Splatt Forum 4.0 for PHP-Nuke 6.0.
Although this is the ONLY version tested for the moment, it is highly
that other versions are open to similar attacks.
There are various possible solutions going around at the forums at
though the forums are in Italian and the English translations are often
Recently, Splatt Forum 4.0 Fix 1 has been released; but this is yet
TECHNICAL DESCRIPTION - EXPLOIT/CONCEPT CODE:
 XSS Vulnerability
Post a message (Anonymous is OK) containing the following message body:
Some test text for fun <script>alert(document.cookie);</script> some more
This causes the rendering of the script upon reading (loading) of the page
the next user. The JS is rendered FIRST, before the user can perform a
 HTML/Code Injection Flaw
Perform a search with the keywords:
Upon rendering of the search results the remote site or any local page
rendered in the IFRAME. I am sure other JS exploits are renderable as well,
especially the IE 5-6 crash exploits (null objects) and remote JS cookie
The vulnerabilities outlined in this advisory and accompanying sample code
been discovered by morning_wood (morning_wood () thepub co za) of Morning
At the time of discovery this vulnerability was considered 0-day as the
testing was performed "on the fly" as a curiosity test. The above exploits
not been circulated through the underground community and are presented
a PUBLIC DISCLOSURE.
Frame4 Security Systems is a new security partner, empowering clients with
necessary knowledge and products to protect and secure their computer
Headquartered in The Netherlands, Frame4 can be reached at +31(0)172-
on the Web at http://www.frame4.com/.
This advisory is a Frame4 Security Systems ("Frame4") publication, all
reserved (c) 2003. You may (re-)distribute the text as long as the content
not changed in any way and with this header text intact. If you want to
this paper on your web site/FTP/Newsgroup/etc., we encourage you to do so,
long as no changes are made without the prior permission of the author(s),
fees are charged and proper credit is given.
IMPORTANT -- THIS DOCUMENT IS FOR INFORMATIONAL PURPOSES ONLY. To the
extent permitted by applicable law, in no event shall Frame4 Security
be liable for any damages whatsoever, (including, without limitation,
for loss of any business profits, business interruption, loss of any
information, or other pecuniary loss) arising out of the use, or inability
use any software, and/or procedures outlined in this document, even if
Security Systems has been advised of the possibility of such damage(s).
are NO warranties with regard to this information.
This advisory is the property of Frame4 Security Systems, all rights
Copyright (c) 1999-2003 Frame4 Security Systems -- http://www.frame4.com/
- Multiple Vulnerabilities in Splatt Forum 4.0 Frame4 Security Systems (May 01)