Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Insanely simple blog - Multiple vulnerabilities Jul 17 2007 10:08AM
joseph giron13 gmail com
Insanely simple blog version 0.5 and below
http://sourceforge.net/projects/insanelysimple2

ISB contains multple vulnerabilities including both XSS, and SQL injection.

First off, the search action fails to strip user content for html allowing a user to input tags. Next, anonymous blog entries can c...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus