Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

BtiTracker Multiple Input Validation and Authentication Bypass Vulnerabilities

BtiTracker is prone to multiple remote vulnerabilities including a multiple cross-site scripting vulnerabilities an SQL-injection vulnerability and multiple authentication-bypass vulnerabilities

Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, execute arbitrary script code in the context of the webserver process, steal cookie-based authentication credentials, gain unauthorized access to the affected application, or exploit latent vulnerabilities in the underlying database.

These issues affect BtiTracker versions prior to 1.4.5.







 

Privacy Statement
Copyright 2009, SecurityFocus