|
OpenBB Multiple Input Validation Vulnerabilities
No exploits are required to leverage these issues. The following proof of concept has been provided: Cross-Site Scripting: http://www.example.com/member.php?action=login&redirect=[XSS] http://www.example.com/myhome.php?action=newmsg&to=blah[XSS] http://www.example.com/post.php?action=mail&TID=1[XSS] http://www.example.com/index.php?redirect=[XSS] SQL injection: http://www.example.com/board.php?FID=1[SQL] http://www.example.com/member.php?action=list&page=1&sortorder=[SQL] http://www.example.com/member.php?action=list&page=1&sortorder=username&perpage=[SQL] http://www.example.com/member.php?action=passwdsend&resetid=blah&id=2[SQL] http://www.example.com/search.php?&sortby=dateline&sort=DESC&q=open&forums%5B[SQL]%5D http://www.example.com/post.php?action=edit&page=1&PID=1[SQL] http://www.example.com/post.php?action=post&FID=1[SQL] http://www.example.com/index.php?CID='[SQL] |
|
|
Privacy Statement |