PunBB Multiple Input Validation Vulnerabilities

An attacker can exploit an SQL-injection vulnerability or arbitrary-code-execution vulnerability via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting victim to follow a malicious URI.

Sample exploit code has been provided:


 

Privacy Statement
Copyright 2010, SecurityFocus