Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
bitweaver <=1.3.1 [injection sql (post) & xss (post)] Nov 09 2006 05:05PM
saps audit gmail com
bitweaver <=1.3.1 [injection sql (post) & xss (post)]
vendor site: http://www.bitweaver.org/
product :bitweaver 1.3.1
bug:injection sql post & multiples xss post
risk : high

severals juicy sql error can be found in the sort_mode var ,
sql (get) :
http://localhost/bitweaver/blogs/list_blogs.php?so...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus