Go Back   Website Hosting - VPS Hosting - Domain Registration Ireland :: Blacknight > Technical Support > Security Notices

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 30-06-05, 10:50 AM
Junior Member
 
Join Date: May 2004
Posts: 18
Default PHP-Nuke "off-site Avatar" Script Insertion Vulner

Input passed to the "Link to off-site Avatar" field isn't properly sanitised before being used. This can be exploited to inject arbitrary HTML and script code, which will be executed in a user's browser session.
Successful exploitation requires that the "Enable remote avatars" setting is enabled (disabled by default).
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 22-07-05, 10:33 PM
Junior Member
 
Join Date: Aug 2003
Posts: 18
Default Impressed

Have to say I'm inpressed at this forum. A lot of hosting companies don't bother to inform clients of issues with Third Party PHP scripts etc.

Take Hosting 365.ie - they take your money and run!!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 28-07-05, 09:09 AM
Junior Member
 
Join Date: May 2004
Posts: 18
Default

Thanks!
We can't cover all 3rd party scripts, but we'll post notices about any scripts that can be installed automatically (see http://www.blacknight.ie/installatron.0.html)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Tags
insertion, offsite avatar, phpnuke, script, vulner

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Gallery EXIF Data Script Insertion Vulnerability niall Security Notices 0 26-08-05 09:58 AM
Coppermine Photo Gallery EXIF Data Script Insertion niall Security Notices 0 22-08-05 09:23 AM
phpBB BBcode "url" Script Insertion Vulnerability niall Security Notices 0 28-07-05 08:47 AM


All times are GMT. The time now is 03:11 PM.


VPS Hosting Web Hosting Ireland Blacknight Blog Blacknight Status

Powered by: vBulletin Version 3.7.3, Copyright ©2000 - 2008, Jelsoft Enterprises Limited.
Blacknight 2005 - 2008 | VPS Hosting

SEO by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17