Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

IDevSpot BizDirectory Multiple SQL Injection and Cross Site Scripting Vulnerabilities

IDevSpot BizDirectory is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied data. The issues include SQL-injection and cross-site scripting vulnerabilities.

Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Versions prior to IDevSpot BizDirectory 2.07 are vulnerable.







 

Privacy Statement
Copyright 2009, SecurityFocus