PHP-Nuke is a PHP based portal management system used at thousands of sites. A Cross Site Scripting vulnerability has been discovered in the PHP-Nuke version 5.5 and prior versions. There is a function called Private Messages in PHP-Nuke by which the registered users of the site can send messages to the other registered users of site. A user can also send a HTML formatted message and can even embed JavaScript in it. Now, if the user sends a malicious JavaScript embedded message to someone then the JavaScript would be executed on the receiver's browser. -------------Sample Message---------------- You have been screwed! ------------------------------------------- Thus it also allows an attacker to reveal the critical information such as cookies related to that site and get hold on his account even on admin. Get this and more at http://hackergurus.tk Regards, Ravish ravishahuja1@yahoo.com http://hackergurus.tk Hacker Gurus:: Geeks With Attitude http://hackergurus.tk Sign up now to recieve all the latest news and updates right in your mailbox.