New Nuke Security Advisories

Posted on Tuesday, June 08, 2004 @ 07:49:20 CDT in Security
by Raven

We are aware that some new exploits/advisories have been issued concerning phpnuke and we are looking into those reports right now. If we find that they are legitimate, we will determine a solution and will make it/them available ASAP.
 
 
click Related        click Share
 
 
Associated Topics

Announcements
 
 

Re: New Nuke Security Advisories (Score: 1)
by chatserv on Tuesday, June 08, 2004 @ 10:22:06 CDT

(User Info | Send a Message) http://www.scriptheaven.net

The one regarding the Reviews module does not apply to PHP-Nuke 7.3 as stated at securityfocus, 7.3 filters the $id variable.

Re: New Nuke Security Advisories (Score: 1)
by chatserv
on Tuesday, June 08, 2004 @ 11:05:41 CDT
(User Info | Send a Message) http://www.scriptheaven.net

Looking closer at the report it seems the vulnerable variable is actually $title, we'll post back on this issue shortly.

 
 

Re: New Nuke Security Advisories (Score: 1)
by xfsunolesphp on Thursday, June 10, 2004 @ 08:50:38 CDT
  
(User Info | Send a Message)

$title = intval($title); is too much to ask?

Re: New Nuke Security Advisories (Score: 1)
by Raven
on Thursday, June 10, 2004 @ 09:51:31 CDT
(User Info | Send a Message)

You can't use a numeric test on a alpha-numeric field. It will always be FALSE and resolve to ZERO..

 
News ©

Site Info

Last SeenLast Seen
  • kguske
  • nextgen
Server TrafficServer Traffic
  • Total: 504,395,848
  • Today: 66,128
Server InfoServer Info
  • Mar 12, 2025
  • 07:11 am CDT