stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


Re: [XSS] PHP-Nuke 7.4 Bugs







Re: [XSS] PHP-Nuke 7.4 Bugs

Re: [XSS] PHP-Nuke 7.4 Bugs 09/07/2004 06:23 PM

Blaine Elzey (Sep 05 2004)




This is a GrokNews Entry: (what is grok?)





Similar Items

Re: [XSS] PHP-Nuke 7.4 Bugs

Grok Headline matches for Re: [XSS] PHP-Nuke 7.4 Bugs

PHP-Nuke Filtering Bugs


PHP-Nuke Filtering Bugs 05/24/2002 11:27 AM

Multiple vulnerabilities PHP-Nuke Video
Gallery Module for PHP-Nuke


Multiple vulnerabilities PHP-Nuke Video
Gallery Module for PHP-Nuke
04/27/2004 12:59 PM
k1LL3r B0y (Apr 26 2004)

(IE/SCOB) Switching Software Because of
Bugs: Some Facts About Software and
Security bugs


(IE/SCOB) Switching Software Because of
Bugs: Some Facts About Software and
Security bugs
07/01/2004 10:30 AM
Drew Copley (Jun 30 2004)

Re: (IE/SCOB) Switching Software Because
of Bugs: Some Facts About Software and
Security bugs


Re: (IE/SCOB) Switching Software Because
of Bugs: Some Facts About Software and
Security bugs
07/07/2004 02:41 PM
Thomas C. Greene (Jul 06 2004)

PHP-Nuke ES OP


PHP-Nuke ES OP 04/15/2004 02:24 PM
Inaguración en SourceForge

RPG-Nuke


RPG-Nuke 11/06/2003 07:19 PM
Getting it together

PHP-Nuke 7.3


PHP-Nuke 7.3 07/21/2004 06:18 AM
PHP Interactive Web Portal System

[XSS] PHP-Nuke 7.4 ViewAdmin Bug


[XSS] PHP-Nuke 7.4 ViewAdmin Bug 09/05/2004 12:39 AM
Pierquinto Manco (Sep 04 2004)

[XSS] PHP-Nuke 7.4 DelAdmin Bug


[XSS] PHP-Nuke 7.4 DelAdmin Bug 09/05/2004 09:29 AM
Pierquinto Manco (Sep 04 2004)

pJirc-Nuke


pJirc-Nuke 09/06/2004 05:09 AM
pJirc Nuke Project

[XSS] PHP-Nuke 7.4 AddMsg Bug


[XSS] PHP-Nuke 7.4 AddMsg Bug 09/07/2004 02:16 PM
Pierquinto Manco (Sep 05 2004)

Port-A-Nuke


Port-A-Nuke 09/03/2004 02:15 PM

Nuke-Board


Nuke-Board 11/01/2003 11:48 AM
Nuke-Board development begins

geoURL, RSS, and PHP-Nuke


geoURL, RSS, and PHP-Nuke 01/14/2003 09:22 AM
Jon of Inphidelphia.com has created a PHP-Nuke module that integrates my RSS parser with the services provided by GeoURL. Just provide the module with your lattitude/longitude coordinates and it will output links to all the blogs near you. You can download Parse_geoURL here.

Newsportal Nuke 0.26


Newsportal Nuke 0.26 09/08/2004 10:10 PM
An adaptation of the original newsportal script.

Nuke Comics 0.5.2


Nuke Comics 0.5.2 04/14/2004 05:07 PM
A comics organizing script for PHP-Nuke.

New Nuke is a blast


New Nuke is a blast 01/27/2004 07:31 PM
Whether running an online community or a blog, PHP-Nuke serves up your content without fuss. PHP-Nuke tries to be all things to all people. ...

[XSS] PHP-Nuke 7.4 Newsletter Injection
Bug


[XSS] PHP-Nuke 7.4 Newsletter Injection
Bug
09/07/2004 02:16 PM
Pierquinto Manco (Sep 05 2004)

Nuke Mosquito, End Malaria?


Nuke Mosquito, End Malaria? 04/26/2004 04:53 AM
An experiment by the United Nations uses nuclear technology to attempt to eradicate the malaria mosquitoes that transmit the disease. The effort is aimed at helping Sub-Saharan Africa.

PHP-Nuke Multiple Vulnerabilities


PHP-Nuke Multiple Vulnerabilities 05/07/2004 07:06 PM
Allowing malicious people to conduct Cross Site Scripting and SQL injection attacks

Multiple vulnerabilities PHP-Nuke


Multiple vulnerabilities PHP-Nuke 06/07/2004 06:58 PM
Dark Bicho (Jun 07 2004)

RE: Multiple vulnerabilities PHP-Nuke


RE: Multiple vulnerabilities PHP-Nuke 06/08/2004 01:43 PM
Jeruvy (Jun 08 2004)

Nuke trouble in Japan


Nuke trouble in Japan 08/09/2004 07:48 AM
USA Today Aug 9 2004 12:01PM GMT

5 Fired In Nuke Lab Scandal


5 Fired In Nuke Lab Scandal 09/15/2004 09:48 PM
CBS News Sep 16 2004 0:41AM GMT

Stewart Brand, pro-nuke?


Stewart Brand, pro-nuke? 04/08/2005 12:19 PM
David Pescovitz: In the new issue of Technology Review, Whole Earth Catalog founder Stewart Brand outlines a surprising new plan for saving the environment, including a case for going nuclear:
So everything must be done to increase energy efficiency and decarbonize energy production. Kyoto accords, radical conservation in energy transmission and use, wind energy, solar energy, passive solar, hydroelectric energy, biomass, the whole gamut. But add them all up and it’s still only a fraction of enough. Massive carbon “sequestration” (extraction) from the atmosphere, perhaps via biotech, is a widely held hope, but it’s just a hope. The only technology ready to fill the gap and stop the carbon dioxide loading of the atmosphere is nuclear power.

Nuclear certainly has problems—accidents, waste storage, high construction costs, and the possible use of its fuel in weapons. It also has advantages besides the overwhelming one of being atmospherically clean. The industry is mature, with a half-century of experience and ever improved engineering behind it. Problematic early reactors like the ones at Three Mile Island and Chernobyl can be supplanted by new, smaller-scale, meltdown-proof reactors like the ones that use the pebble-bed design. Nuclear power plants are very high yield, with low-cost fuel. Finally, they offer the best avenue to a “hydrogen economy,” combining high energy and high heat in one place for optimal hydrogen generation.

The storage of radioactive waste is a surmountable problem (see “A New Vision for Nuclear Waste,” December 2004). Many reactors now have fields of dry-storage casks nearby. Those casks are transportable. It would be prudent to move them into well-guarded centralized locations. Many nations address the waste storage problem by reprocessing their spent fuel, but that has the side effect of producing material that can be used in weapons. One solution would be a global supplier of reactor fuel, which takes back spent fuel from customers around the world for reprocessing. That’s the kind of idea that can go from “Impractical!” to “Necessary!” in a season, depending on world events.
Link


Are UK Nuke Reactors in Trouble?


Are UK Nuke Reactors in Trouble? 03/27/2005 03:48 PM
Technocrat.net Mar 27 2005 7:15PM GMT

PHP-Nuke 7.4 Multiple XSS
Vulnerabilities Patch


PHP-Nuke 7.4 Multiple XSS
Vulnerabilities Patch
09/07/2004 04:13 PM
Pierquinto Manco (Sep 05 2004)

Community News: Vulnerabilities in
PHP-Nuke


Community News: Vulnerabilities in
PHP-Nuke
05/07/2004 07:54 AM
In a new security advisory posted late yesterday, Secunia has a few new issues with PHP-Nuke (v6.x and v7.x):
  • If error messages hasn't been turned off in PHP, the "Downloads" module will return error messages if an invalid value is supplied to the "show" parameter. This can be exploited to reveal the installation path.
  • Input passed to the "ttitle" and "sid" parameters in the "Downloads" module isn't properly verified before it is returned to the user. This can be exploited to execute arbitrary HTML or script code in a user's browser session in context of an affected site by tricking the user into visiting a malicious website or follow a specially crafted link.
  • Input passed to the "orderby" and "sid" parameters in the "Downloads" module isn't properly verified before it is used in an SQL insert query. This can be exploited by malicious people to manipulate SQL queries by injecting arbitrary SQL code.
My personal favorite - the solution: Use another product. Somehow, I think most of the PHP community could have told you that...

Key figure in nuke trafficking arrested


Key figure in nuke trafficking arrested 05/28/2004 03:27 PM

Wired News: Vaporware: Nuke 'Em if Ya
Got 'Em


Wired News: Vaporware: Nuke 'Em if Ya
Got 'Em
01/22/2004 02:49 AM

Wired News: Vaporware: Nuke 'Em if
Ya Got 'Em


Wired News: Vaporware: Nuke 'Em if
Ya Got 'Em
01/22/2004 02:13 AM
Vaporware: Nuke 'Em if Ya Got 'Em .. Wired's Annual Vaporware Awards .. premios al Vaporware .. vaporware .. Wired

wired.com/news/technology/0,1282,61935,00.html
track this site | 13 links


Bush Gets Look at Nuke Parts From Libya
(AP)


Bush Gets Look at Nuke Parts From Libya
(AP)
07/12/2004 05:27 AM
AP - In a Southern state he hopes to win again in November, President Bush is getting a look at nuclear weapons parts turned over by Libya while working to convince voters that his administration is making steady progress in the war on terrorism.

U.S.: N. Korea Threatened to Test Nuke
(AP)


U.S.: N. Korea Threatened to Test Nuke
(AP)
06/25/2004 05:32 AM
AP - North Korea has threatened to test a nuclear weapon unless Washington accepts Pyongyang's conditions for a freeze of its nuclear weapons program, a senior U.S. official said.

Libya Nuke Drawings Likely From Pakistan
(AP)


Libya Nuke Drawings Likely From Pakistan
(AP)
02/15/2004 03:41 PM
AP - Drawings of a nuclear warhead that Libya surrendered as part of its decision to renounce weapons of mass destruction are of 1960s Chinese design, but likely came from Pakistan, diplomats and experts told The Associated Press on Sunday.

Poll: No Nation Should Have Nuke Weapons
(AP)


Poll: No Nation Should Have Nuke Weapons
(AP)
03/30/2005 11:45 PM
AP - Though the Soviet Union is gone, the nuclear fears that fueled the Cold War haven't disappeared. Most Americans think nuclear weapons are so dangerous that no country should have them, and a majority believe it's likely that terrorists or a nation will use them within five years.

[XSS]/SQL Injection PHP-Nuke Delete
Message(s) Bug


[XSS]/SQL Injection PHP-Nuke Delete
Message(s) Bug
09/08/2004 05:51 PM
bima tampan (Sep 07 2004)

U.S.: Iran May Be Running Nuke Programs
(AP)


U.S.: Iran May Be Running Nuke Programs
(AP)
04/27/2004 05:28 PM
AP - Iran may be running a covert military nuclear program parallel to the peaceful one it has opened to international scrutiny in efforts to dispel suspicions it has weapons ambitions, U.S. officials said Tuesday.

Nuke Lab Lawyer Defends Actions


Nuke Lab Lawyer Defends Actions 03/13/2003 10:23 AM
Testifying before a House committee, the chief attorney for Los Alamos Labs says he didn't mean to obstruct an FBI investigation of the embattled facility. By Noah Shachtman.

FreeSoftwareReviews: PHP-Nuke Security
Tools


FreeSoftwareReviews: PHP-Nuke Security
Tools
09/09/2004 09:01 AM
OpenSource at its best: A comprehensive overview on Security Tools for PHPNuke & osc2nuke. Here is a comparison of the advertised features of 7 tools for protecting PHP-Nuke-based websites. Each tool has its own unique features to help you protect your Php-Nuke-based website. This comparison can help you choose among alternatives. NOW INCLUDES SENTINEL 2.0.2, Intrusos and myNukeSecurity 1.01.
Grok Description matches for Re: [XSS] PHP-Nuke 7.4 Bugs
GrokA matches for Re: [XSS] PHP-Nuke 7.4 Bugs

Re: [XSS] PHP-Nuke 7.4 Bugs

The following phrases have been identified by the grok system as matching this entry:

















Also check out:


Grok

Ipod Porn on the
Rise

Brief Abstract of
Wikipedia's
Mesothelioma Cancer
page

Get first aid
instructions in your
cell phone

IE is crap
JSPWiki gains
podcasting support

Itanium not meeting
Intel's goals

Tim Blair: URBANITE
REQUESTS DESTRUCTION

onegoodmove.org/1gm
- Love Docs

CNN.com - Two
muppets named top
scientists - Sep 5,
2004

MSNBC - Troops
battle al-Sadr
loyalists; at least
36 killed

CNN.com - Fighting
rages in Baghdad's
Sadr City - Sep 7,
2004

One of the best
Bushism's yet!

Iraq Coalition
Casualties

Connect four 3D
SnakeSkin
Application Toolkit

Ma'at
Verizon switches on
speedier DSL

VoIP and the
Enterprise: Finding
the ROI (NewsFactor)

Novell, Red Hat, Sun
Pledge Support for
AMD's Dual-Core
Chips (NewsFactor)

Nokia To Offer
BlackBerry Software
(NewsFactor)

First Look:
Rave-MP's Flashy New
MP3 Player (PC
World)

Tivo, Netflix Close
to Internet Movie
Deal - Report
(Reuters)

Wireless Technology
to Rival Cable, DSL
- Intel (Reuters)

Calif. to Sue
Diebold Over False
Claims (Reuters)

South Africa:
Ethniks Pilots HP
4-1 Shared Computing

Cisco Launches
Opportunity
Incentive Program

TriQuint Semi Guides
Lower

AT&T Pens Staples
Pact

Former Silicon
Valley banker
Quattrone faces
likely prison time

Halo: Combat Evolved
ret

HDS Hungry for High
End with New
Platform

This isn't a race.
This is a sea change
in computing

Intel: The world
will be dual-core by
2006

Google Can Now Index
. . . Flash! An
Interview with
Michael Marshall

FAIR: If Only They
Had Invented the
Internet - The
Failure of
Fact-Checking at the
Republican
Convention

Red Hat Releases New
Linux Update

Nvida at IDF:
Graphics Innovations
are Fueling Demand

fun with facts
Shop Owner on Spot
Over Polka Dot Tree
(AP)

Coroner Discussing
Gun Safety Shoots
Self (AP)

MSN to launch
business cards for
kids

Hitachi upgrades
storage line

Lexmark, Dell and
IBM printers can
pose shock hazard

Investigators Say
Ex-Medicare Chief
Should Repay Salary

Apple: Security
Update 2004-09-07

New chief for
Algeria's Islamists

Macromedia Tunes
Conferencing Pricing
for SMBs

Macromedia Makes Web
Conferencing a
Breeze

Great Big Stuff
Oracle in a buying
mood, president says

Unisys joins Red Hat
Partner Community

FedEx CEO to lead
industry security
task force

Lexmark recalls
39,000 laser
printers

Open-source backers
revolt against
Microsoft antispam
plan

7-Eleven deploys HP
technology in 5,300
U.S. stores

what is grok?