XSS & multiple SQL Injection en PHP-Nuke 6.x y 7.x

[ Admin-level authentication bypass in phpnuke 6.x-7.2]
Esta es la mas peligrosa para todas las web :S
http://www.securityfocus.com/archive/1/360136
[ User-level authentication bypass in phpnuke 6.x-7.2 ]
http://www.securityfocus.com/archive/1/360129
[ Cross-Site Scripting aka XSS in phpnuke 6.x-7.2 part 3 ]
http://www.securityfocus.com/archive/1/360156
Parches:
http://www.phpnuke.org/modules.php?name=News&file=article&sid=6679
Extraido de RZW
0 comentarios