Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Zeroboard Multiple Remote Vulnerabilities

Zeroboard is prone to multiple vulnerabilities, including multiple SQL-injection issues, multiple security-bypass issues, a cross-site scripting issue, and local and remote file-include issues.

Successful exploits may allow attackers to:

- access or modify data
- exploit latent vulnerabilities in the underlying database
- obtain sensitive information
- execute arbitrary script code in the context of the webserver
- execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site
- bypass certain security restrictions

A successful attack will compromise the application and may help in further attacks.

The issues affect Zeroboard 4 pl8; other versions may also be vulnerable.







 

Privacy Statement
Copyright 2008, SecurityFocus