TR Forum SQL Injection And Authentication Bypass vulnerabilities

Tr Forum is prone to an SQL-injection issue and an authentication-bypass issue because the application fails to properly sanitize user-supplied input.

A successful exploit could allow an attacker to compromise the application, access or modify data, exploit vulnerabilities in the underlying database implementation, and gain administrative access to the affected application.

Version 2.0 is vulnerable to these issues; other versions may also be affected.


 

Privacy Statement
Copyright 2010, SecurityFocus