Home Private Messages Search
CPG Dragonfly™ CMS stopsoftwarepatents.eu petition banner
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security :: Archives ⇒ XSS That works in cpgnuke! :: Archived


XSS That works in cpgnuke! :: Archived
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Post new topic    Revive this topic    Printer Friendly Page     Forum Index ⇒  Security

Topic Archived View previous topic :: View next topic  
Author Message
musox
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Apr 20, 2004
Posts: 325

PostPosted: Tue Jul 20, 2004 7:53 am
Post subject: XSS That works in cpgnuke!

Please see this article on XSS in the Search module. It works on ALL of my cpgnuke 8.2 sites. I did not try it on cpgnuke.com... I'll let the admins do that. Wink

Please help!

- MusOX

_________________
../musox.com
Hosted by: Site5.com

musox's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux / 1.3.39 / 4.1.22 / 4.4.7 / 9.2.1
Back to top
View user's profile Visit poster's website Photo Gallery
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Tue Jul 20, 2004 8:17 am
Post subject: Re: XSS That works in cpgnuke!

Thanks Musox - noted - the Security Team has it covered - if serious, we'll get them to post a fix, but it's certainly covered in 8.2b.

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
alexm
500+ Posts Club
500+ Posts Club

Offline Offline
Joined: Apr 20, 2004
Posts: 574
Location: Lafayette, LA USA
PostPosted: Tue Jul 20, 2004 3:58 pm
Post subject: Re: XSS That works in cpgnuke!

musox wrote:
Please see this article on XSS in the Search module. It works on ALL of my cpgnuke 8.2 sites. I did not try it on cpgnuke.com... I'll let the admins do that. Wink
Please help!
- MusOX

You can grab the fixed search module's index.php from here:

cvs.sourceforge.net/vi...p;view=log

This is the one that will be in the 8.2b release, so all you'd need to do is overwrite your existing file (after backing it up, of course).

There are several other XSS holes that are patched in what will be 8.2b, so if you're concerned about XSS, it would be wise to upgrade when the release comes out. Heck, there's enough security and minor bugfixes in 8.2b that everyone should upgrade when it becomes available. Smile

alex


alexm's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Shared Host / Linux / Apache 1.3.23 / Mysql 3.23.58 / PHP 4.3.3 / CPG 8.2b & 8.3CVS
Back to top
View user's profile Visit poster's website Photo Gallery
musox
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Apr 20, 2004
Posts: 325

PostPosted: Tue Jul 20, 2004 4:52 pm
Post subject: Re: XSS That works in cpgnuke!

ok... so enough with the tease... when is 8.2b being released? Wink

_________________
../musox.com
Hosted by: Site5.com

musox's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux / 1.3.39 / 4.1.22 / 4.4.7 / 9.2.1
Back to top
View user's profile Visit poster's website Photo Gallery
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Tue Jul 20, 2004 4:58 pm
Post subject: Re: XSS That works in cpgnuke!

when it's ready.

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
musox
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Apr 20, 2004
Posts: 325

PostPosted: Tue Jul 20, 2004 5:07 pm
Post subject: Re: XSS That works in cpgnuke!

Smartass... I love it Exclamation

_________________
../musox.com
Hosted by: Site5.com

musox's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux / 1.3.39 / 4.1.22 / 4.4.7 / 9.2.1
Back to top
View user's profile Visit poster's website Photo Gallery
Viperal
Supporter
Supporter

Offline Offline
Joined: May 01, 2004
Posts: 858
Location: New York
PostPosted: Tue Jul 20, 2004 5:30 pm
Post subject: Re: XSS That works in cpgnuke!

musox wrote:
Smartass... I love it Exclamation

Yep that all you'll get from us Wink Razz Razz .

BTW nice site BrainSmashR would be happy. Stole you background btw, hope you don't mind.

Also 8.2b is in the CVS (http://cvs.sourceforge.net/viewcvs.py/phpnuke65-cpg/), use at you own rish , but as far as i know it ok, backup if your going to use it, (all you have to do is replace your files)

_________________
What is The Viperal ?
Email: viperal1 @ gmail.com

Viperal please enter your server specs in your user profile! Crying or Very sad
Back to top
View user's profile Visit poster's website AIM Address MSN Messenger Yahoo Messenger
musox
Platinum Supporter
Platinum Supporter

Offline Offline
Joined: Apr 20, 2004
Posts: 325

PostPosted: Tue Jul 20, 2004 6:57 pm
Post subject: Re: XSS That works in cpgnuke!

don't mind about the BG at all... Apple made it anyways Wink I'll just wait for the full release... till then... "Search will be disable".

- MusOX

_________________
../musox.com
Hosted by: Site5.com

musox's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux / 1.3.39 / 4.1.22 / 4.4.7 / 9.2.1
Back to top
View user's profile Visit poster's website Photo Gallery
Śyama_Dāsa
Developer
Developer

Offline Offline
Joined: Apr 19, 2004
Posts: 2048
Location: Dragonfly CMS Tribe
PostPosted: Tue Jul 20, 2004 8:21 pm
Post subject: Re: XSS That works in cpgnuke!

8.2b is released.

_________________
AKA Akamu / Read these and your life will be successful | Find a Repair
--
Mods and Professional Support via YIM

Śyama_Dāsa's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
win32 / Apache 1.3.33 / MySQL 4.1.16/PHP 4.4/CPG-CVS ( browsers: Mozilla 1.7.x / IE6 / Opera 8.0)
Back to top
View user's profile Visit poster's website Yahoo Messenger Photo Gallery
Display posts from previous:   
Post new topic    Revive this topic    Printer Friendly Page    Forum Index ⇒  Security
Page 1 of 1
All times are GMT

Archive Revive
Username:
This is an archived topic - your reply will not be appended here.
Instead, a new topic will be generated in the active forum.
The new topic will provide a reference link to this archived topic.
 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

pročitaj još...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy