FYI…

PHP-Nuke "off-site Avatar" Script Insertion Vulnerability

- http://secunia.com/advisories/15829/
Release Date: 2005-06-27
Critical: Moderately critical
Impact: Cross Site Scripting
Where:From remote
Solution Status: Unpatched
Software: PHP-Nuke 7.x
"Description:
…vulnerability in PHP-Nuke, which can be exploited by malicious people to conduct script insertion attacks.
Input passed to the "Link to off-site Avatar" field isn't properly sanitised before being used.
Solution:
Edit the source code to ensure that input is properly sanitised.
Disable the "Enable remote avatars" setting…"

=============================================

PHP-Fusion Two Vulnerabilities

- http://secunia.com/advisories/15830/
Release Date: 2005-06-27
Critical: Moderately critical
Impact: Cross Site Scripting
Exposure of sensitive information
Where: From remote
Solution Status: Unpatched
"Description:
…2 vulnerabilities in PHP-Fusion, which can be exploited by malicious people to conduct script insertion attacks or disclose sensitive information… The vulnerabilities have been confirmed in version 6.00.105. Other versions may also be affected.
Solution:
1) Edit the source code to ensure that input is properly sanitised.
2) Configure the web server to restrict access to database backup directory…"

:ph34r: