This advisory details a file inclusion vulnerability in PHP-Nuke 8.2.4 via the `newlang` parameter and a reflected XSS vulnerability in the Your_Account module via the `redirect` parameter, both stemming from unsafe use of `import_request_variables`.
Classification
Writeup 90%
Attack Type
Xss | Info Leak
Complexity
Trivial
Reliability
Reliable
Target:PHP-Nuke 8.2.4 and possibly below
No auth needed
Prerequisites:PHP-Nuke installation with `register_globals` disabled · Access to the target web application