mailing list archives
phpkit suffers (realy stupid) XSS vuln.
From: Yanosz <yanosz () gmx net>
Date: Tue, 30 Mar 2004 22:26:19 +0200
Version: 1.6.03 others are probably affected as well.
Status: Vendor has been notified weeks ago but refuses to answer or take any
phpkit is a simple German cms / portal software written in php similar to
phpbb / phpnuke and is quite popular in Germany. All session information is
stored in cookies - thus a attacker can easily steal session data or hashed
injections - all html-tags appear in the victim's browser.
That's odd - <script... ;)
The source also seems to be vulnerably to SQL-injections - good luck ;)
Don't use this software. These guys do not seem to know what they are doing.
Full-Disclosure - We believe in it.
- phpkit suffers (realy stupid) XSS vuln. Yanosz (Mar 30)