| Topic Archived |
View previous topic :: View next topic |
| Author |
Message |
musox Platinum Supporter


Offline Joined: Apr 20, 2004 Posts: 325
|
Posted: Tue Jul 20, 2004 7:53 am Post subject: XSS That works in cpgnuke! |
|
Please see this article on XSS in the Search module. It works on ALL of my cpgnuke 8.2 sites. I did not try it on cpgnuke.com... I'll let the admins do that.
Please help!
- MusOX
_________________ ../musox.com
Hosted by: Site5.com
musox's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux / 1.3.39 / 4.1.22 / 4.4.7 / 9.2.1
|
|
| Back to top |
|
 |
Phoenix • Many Posts •


Offline Joined: Apr 19, 2004 Posts: 8799 Location: Netizen
|
Posted: Tue Jul 20, 2004 8:17 am Post subject: Re: XSS That works in cpgnuke! |
|
Thanks Musox - noted - the Security Team has it covered - if serious, we'll get them to post a fix, but it's certainly covered in 8.2b.
_________________ • DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin •
Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
|
|
| Back to top |
|
 |
alexm 500+ Posts Club


Offline Joined: Apr 20, 2004 Posts: 574 Location: Lafayette, LA USA
|
Posted: Tue Jul 20, 2004 3:58 pm Post subject: Re: XSS That works in cpgnuke! |
|
| musox wrote: |
Please see this article on XSS in the Search module. It works on ALL of my cpgnuke 8.2 sites. I did not try it on cpgnuke.com... I'll let the admins do that. 
Please help!
- MusOX |
You can grab the fixed search module's index.php from here:
cvs.sourceforge.net/vi...p;view=log
This is the one that will be in the 8.2b release, so all you'd need to do is overwrite your existing file (after backing it up, of course).
There are several other XSS holes that are patched in what will be 8.2b, so if you're concerned about XSS, it would be wise to upgrade when the release comes out. Heck, there's enough security and minor bugfixes in 8.2b that everyone should upgrade when it becomes available.
alex
alexm's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Shared Host / Linux / Apache 1.3.23 / Mysql 3.23.58 / PHP 4.3.3 / CPG 8.2b & 8.3CVS
|
|
| Back to top |
|
 |
musox Platinum Supporter


Offline Joined: Apr 20, 2004 Posts: 325
|
Posted: Tue Jul 20, 2004 4:52 pm Post subject: Re: XSS That works in cpgnuke! |
|
ok... so enough with the tease... when is 8.2b being released?
_________________ ../musox.com
Hosted by: Site5.com
musox's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux / 1.3.39 / 4.1.22 / 4.4.7 / 9.2.1
|
|
| Back to top |
|
 |
Phoenix • Many Posts •


Offline Joined: Apr 19, 2004 Posts: 8799 Location: Netizen
|
|
| Back to top |
|
 |
musox Platinum Supporter


Offline Joined: Apr 20, 2004 Posts: 325
|
Posted: Tue Jul 20, 2004 5:07 pm Post subject: Re: XSS That works in cpgnuke! |
|
Smartass... I love it
_________________ ../musox.com
Hosted by: Site5.com
musox's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux / 1.3.39 / 4.1.22 / 4.4.7 / 9.2.1
|
|
| Back to top |
|
 |
Viperal Supporter


Offline Joined: May 01, 2004 Posts: 858 Location: New York
|
Posted: Tue Jul 20, 2004 5:30 pm Post subject: Re: XSS That works in cpgnuke! |
|
| musox wrote: |
Smartass... I love it  |
Yep that all you'll get from us  .
BTW nice site BrainSmashR would be happy. Stole you background btw, hope you don't mind.
Also 8.2b is in the CVS (http://cvs.sourceforge.net/viewcvs.py/phpnuke65-cpg/), use at you own rish , but as far as i know it ok, backup if your going to use it, (all you have to do is replace your files)
_________________ What is The Viperal ?
Email: viperal1 @ gmail.com
Viperal please enter your server specs in your user profile!
|
|
| Back to top |
|
 |
musox Platinum Supporter


Offline Joined: Apr 20, 2004 Posts: 325
|
Posted: Tue Jul 20, 2004 6:57 pm Post subject: Re: XSS That works in cpgnuke! |
|
don't mind about the BG at all... Apple made it anyways  I'll just wait for the full release... till then... "Search will be disable".
- MusOX
_________________ ../musox.com
Hosted by: Site5.com
musox's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) Linux / 1.3.39 / 4.1.22 / 4.4.7 / 9.2.1
|
|
| Back to top |
|
 |
Śyama_Dāsa Developer


Offline Joined: Apr 19, 2004 Posts: 2048 Location: Dragonfly CMS Tribe
|
Posted: Tue Jul 20, 2004 8:21 pm Post subject: Re: XSS That works in cpgnuke! |
|
8.2b is released.
_________________ AKA Akamu / Read these and your life will be successful | Find a Repair
--
Mods and Professional Support via YIM
Śyama_Dāsa's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS) win32 / Apache 1.3.33 / MySQL 4.1.16/PHP 4.4/CPG-CVS ( browsers: Mozilla 1.7.x / IE6 / Opera 8.0)
|
|
| Back to top |
|
 |
|
|