Blursoft Blur6ex Multiple Input Validation Vulnerabilities



These issues can be exploited through a web client.

Example URIs have been provided:

http://www.example.com/[blur6ex_dir]/index.php?shard=[XSS_here]
http://www.example.com/[blur6ex_dir]/index.php?shard=login&action=g_error&errormsg=[XSS_here]

http://www.example.com/[blur6ex_dir]/index.php?shard=blog&action=g_reply&ID=[SQL_here]
http://www.example.com/[blur6ex_dir]/index.php?shard=blog&action=g_permaPost&ID=[SQL_here]
http://www.example.com/[blur6ex_dir]/index.php?shard=content&action=g_viewContent&ID=[SQL_here]


 

Privacy Statement
Copyright 2010, SecurityFocus