bcoos Multiple Input Validation Vulnerabilities

The 'bcoos' program is prone to multiple input-validation vulnerabilities, including a local file-include issue, an arbitrary file-upload issue, and an SQL-injection issue. These issues occur because the application fails to properly sanitize user-supplied input.

Exploiting these issues may allow an unauthorized user to view files and execute local scripts, execute arbitrary script code, access or modify data, or exploit latent vulnerabilities in the underlying database implementation.

This issue affects bcoos 1.0.10; other versions may also be affected.


 

Privacy Statement
Copyright 2010, SecurityFocus