PostNuke XSS 0.760{RC2,RC3}

Risk: Low
Local: No
Remote: Yes

CVSS Base Score: 2.6/10
Impact Subscore: 2.9/10
Exploitability Subscore: 4.9/10
Exploit range: Remote
Attack complexity: High
Authentication: No required
Confidentiality impact: None
Integrity impact: Partial
Availability impact: None

[PostNuke XSS 0.760{RC2,RC3} cXIb8O3.6] Author: Maksymilian Arciemowicz ( cXIb8O3 ) Date: 4.3.2005 from SECURITYREASON.COM - --- 0.Description --- PostNuke: The Phoenix Release (0.750) PostNuke is an open source, open developement content management system (CMS). PostNuke started as a fork from PHPNuke ( and provides many enhancements and improvements over the PHP-Nuke system. PostNuke is still undergoing development but a large number of core functions are now stabilising and a complete API for third-party developers is now in place. If you would like to help develop this software, please visit our homepage at You can also visit us on our IRC Server channel #postnuke-support #postnuke-chat #postnuke Or at the Community Forums located at: - --- 1. Cross Site Scripting in RSS module --- 1.0 http://[HOST]/[DIR]/modules/RSS/pnincludes/scripts/magpie_slashbox.php?rss_url=[XSS] 1.1 http://[HOST]/[DIR]/modules/RSS/pnincludes/scripts/magpie_simple.php?url=">[XSS] 1.2 http://[HOST]/[DIR]/modules/RSS/pnincludes/scripts/magpie_debug.php?url=%22%3E[XSS] - --- 2. Full path disclosure in RSS module --- 2.0 http://[HOST]/[DIR]/modules/RSS/pnincludes/scripts/simple_smarty.php - --- Warning: main(/home/kellan/projs/magpierss/scripts/Smarty/Smarty.class.php) [function.main]: failed to open stream: No such file or directory in /www/PostNuke-0.760-RC3/html/modules/RSS/pnincludes/scripts/simple_smarty.php on line 8 Fatal error: main() [function.require]: Failed opening required '/home/kellan/projs/magpierss/scripts/Smarty/Smarty.class.php' (include_path='.:') in /www/PostNuke-0.760-RC3/html/modules/RSS/pnincludes/scripts/simple_smarty.php on line 8 - --- - --- 3. How to fix --- PostNuke 0.760-RC4b but this version is RC. - --- 4.Contact --- Author: Maksymilian Arciemowicz

{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

