Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Ourvideo CMS Multiple Input Validation Vulnerabilities

Attackers can exploit these issues using a browser. To exploit a cross-site scripting issue, an attacker must entice an unsuspecting user to follow a specially crafted URI.

The following example URIs are avaialble:

http://www.example.com/path/phpi/edit_top_feature.php?include_connection=[SHELL]
http://www.example.com/path/phpi/edit_topics_feature.php?include_connection=[SHELL]
http://www.example.com/path/phpi/rss.php?prefix=[LFI]
http://www.example.com/path/phpi/login.php?top_page=[XSS]
http://www.example.com/path/phpi/login.php?end_page=[XSS]







 

Privacy Statement
Copyright 2009, SecurityFocus