Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

427BB Multiple SQL Injection and Cross-Site Scripting Vulnerabilities

An attacker can exploit these issues through a browser. The attacker can exploit the cross-site scripting issue by enticing an unsuspecting user to follow a malicious URI.

The following example URI is available:

http://www.example.com/showpost.php?ForumID=1&post=1 union select 1,UserName,3,4,5,Password,7 FROM 427bb_personal WHERE ID=1--







 

Privacy Statement
Copyright 2009, SecurityFocus