XSS and PHP Code Insertion Vulnerabilities in QLnews
- XSS and PHP Code Insertion Vulnerabilities in QLnews
- Last Update
- 2006.04.09 Exploitation code published
- CVE-2006-1575 CVE-2006-1576
- Risk Level
- Multiple Vulnerabilities
- Unpatched. No reply from developer(s)
- Vulnerable Software
- QLnews (http://www.vscripts.pl/)
- Not available
- Discovered by
- Aliaksandr Hartsuyeu (eVuln.com)
Multiple Vulnerabilities found in QLnews (http://www.vscripts.pl/) script.
1. Cross-Site Scripting.
Vulnerable Script: news.php
Parameters autorx, newsx are not properly sanitized. This can be used to post arbitrary HTML or web script code.
2. PHP Code Insertion.
Administrator has an ability to edit variable values in config.php file. This can be used to insert arbitrary PHP code into config file which executes by every php-script.
System access is possible.
Condition: magic_quotes_gpc = off
1. Cross-Site Scripting Example.
2. PHP Code Insertion Example.
Number of news on main page: 5"; [php_code] $aa="
Solution for "XSS and PHP Code Insertion Vulnerabilities in QLnews" is not available. Check vendor's website for updates.
Order Source Code Review made by eVuln team
Protect against attacks by source code audit of your website done by Aliaksandr Hartsuyeu.The task will be done by experts in website security.