Easebay Resources Paypal Subscription Manager Multiple Input Validation Vulnerabilities

To exploit a cross-site scripting issue:

An attacker can exploit this issue by enticing an unsuspecting user into following a malicious URI.

An example URI has been provided:

http://www.example.com/psm/admin/memberlist.php?keyword=[SQl]&p=a&by=1&sbmt1=++Search++&init_row=0&sort=create_time&sq=desc&status=1

To exploit an SQL-injection issue:

An attacker can exploit this issue via a web client.

An example URI has been provided:

http://www.example.com/psm/admin/edit_member.php?username=Admin=[XSS]


 

Privacy Statement
Copyright 2010, SecurityFocus