Advisory: phpFK 7.2.5 Multiple Cross-site Scripting Vulnerabilities Advisory ID: SSCHADV2011-022 Author: Stefan Schurtz Affected Software: Successfully tested on phpFK 7.2.5 Vendor URL: http://www.frank-karau.de/ Vendor Status: informed CVE-ID: - ========================== Vulnerability Description: ========================== phpFK 7.2.5 is prone to multiple Cross-site scripting vulernabilities ================== Technical Details: ================== http:///phpfk_php_forum_7.2.5/faq.php?'"/> http:///phpfk_php_forum_7.2.5/ranking.php?'"/> http:///phpfk_php_forum_7.2.5/search.php?'"/> http:///phpfk_php_forum_7.2.5/ranking.php?sort=0&page=1'"/> http:///phpfk_php_forum_7.2.5/user.php?user='"/> http:///phpfk/ranking.php?sort=1&page=1." Backend http:///phpfk/ap/?nav=user&page=groups_edit&group=. ========= Solution: ========= ranking.php - '.$_TEXT['LOGIN_USERNAME'].' + '.$_TEXT['LOGIN_USERNAME'].' - '.$_TEXT['POINTS'].' + '.$_TEXT['POINTS'].' - '.$_TEXT['TIME_OF_REGISTRATION'].' + '.$_TEXT['TIME_OF_REGISTRATION'].' - '.$_TEXT['TIME_OF_LAST_VISIT'].' + '.$_TEXT['TIME_OF_LAST_VISIT'].' /include/page_top.php -
+ ==================== Disclosure Timeline: ==================== 02-Oct-2011 - informed developers 04-Oct-2011 - release date of this security advisory ======== Credits: ======== Vulnerabilities found and advisory written by Stefan Schurtz. =========== References: =========== http://www.frank-karau.de/ http://www.rul3z.de/advisories/SSCHADV2011-022.txt